ncforgotten
Topic Starter
hi my name is jordan and my father recently got a nasty virus. i do a little IT and networking, so i'm familiar with how to work a pc here and there, lol. there were problems as such, the clock was in military time followed by a colon and the words virus alert or attempt, there were also programs missing off the desktop, as well as things like, when i opened the start bar, all of the items on the right side were missing, except for access program defaults. the "all programs" and "log-off" icons were also missing as well as when i clicked on my computer(after going and adding those shortcuts back to the start bar) it wasn't displaying my hard drive C:/ or my disk drive… so i removed all the programs in add/remove programs that weren't there before, and ran combo fix, after that my pc reboot, and my pc seemed to be ok after that, however the clock is still in military time and i haven't been able to put it back to normal, i also tried to run HiJackThis and the PC wont let me run it, however here are 2 logs that i got from the results of combo-fix
ComboFix 08-07-15.4 - Carl 2008-07-17 21:03:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.596 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Carl\Favorites\Error Cleaner.url
C:\Documents and Settings\Carl\Favorites\Privacy Protector.url
C:\Documents and Settings\Carl\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\evgratsm.dll
C:\WINDOWS\ewkb.exe
C:\WINDOWS\kvxqmtre.dll
C:\WINDOWS\system32\aberzw.dll
C:\WINDOWS\system32\apmedfel.dll
C:\WINDOWS\system32\bbabLRqr.ini
C:\WINDOWS\system32\bbabLRqr.ini2
C:\WINDOWS\system32\cwuhembh.dll
C:\WINDOWS\system32\hbmehuwc.ini
C:\WINDOWS\system32\ljJDWNGA.dll
C:\WINDOWS\system32\mlJBTjhH.dll
C:\WINDOWS\system32\pdgqvqqb.dll
C:\WINDOWS\system32\rqRLbabb.dll
C:\WINDOWS\system32\vloxqb.dll
C:\WINDOWS\system32\x64
—– BITS: Possible infected sites —–
hxxp://www.dellsupportõj
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-17 20:59 . 2008-07-17 20:59 d——– C:\WINDOWS\LastGood.Tmp
2008-07-17 20:59 . 2008-07-17 20:59 d——– C:\Program Files\Windows Live Safety Center
2008-07-16 19:28 . 2008-07-16 19:28 d——– C:\$AVG8.VAULT$
2008-07-16 18:07 . 2008-07-17 20:34 d——– C:\Documents and Settings\Carl\Application Data\TmpRecentIcons
2008-07-16 18:07 . 2008-07-16 15:29 147,456 –a—— C:\WINDOWS\agpqlrfm.exe
2008-07-15 16:10 . 2008-07-15 16:12 d——– C:\Program Files\BearFlix
2008-07-15 16:10 . 2008-07-17 17:32 d——– C:\My Downloads
2008-07-15 15:59 . 2008-07-15 17:35 d——– C:\Documents and Settings\Carl\Application Data\LimeWire
2008-07-15 12:19 . 2007-08-13 18:54 33,792 –a—— C:\WINDOWS\system32\dllcache\custsat.dll
2008-07-12 16:27 . 2008-07-12 16:27 d–hs—- C:\Documents and Settings\Carl\UserData
2008-07-12 15:57 . 2008-07-12 16:32 d——– C:\Documents and Settings\Carl\Application Data\Multi-Note
2008-07-12 12:14 . 2008-07-12 12:14 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-10 12:23 . 2008-07-10 12:23 d——– C:\Program Files\Alwil Software
2008-07-10 12:18 . 2008-05-01 19:45 d——– C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-10 12:18 . 2008-07-17 17:34 d——– C:\Documents and Settings\Administrator
2008-07-09 16:55 . 2008-07-17 21:08 d——– C:\MDT
2008-07-09 16:27 . 2008-07-09 16:27 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-09 03:02 . 2006-08-21 02:14 128,896 ——— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-07-09 03:02 . 2006-08-21 02:14 23,040 ——— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-07-09 03:02 . 2006-08-21 05:21 16,896 ——— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-07-08 21:30 . 2008-07-15 12:27 d——– C:\Documents and Settings\Carl\Application Data\OpenOffice.org2
2008-07-08 21:29 . 2008-07-08 21:29 d——– C:\Program Files\OpenOffice.org 2.4
2008-07-08 20:43 . 2008-07-10 12:19 d——– C:\Program Files\ThreatFire
2008-07-08 20:43 . 2008-07-08 20:43 d——– C:\Documents and Settings\All Users\Application Data\PC Tools
2008-07-08 20:43 . 2008-04-24 16:52 12,608 –a—— C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-07-08 20:29 . 2008-07-17 17:37 d——– C:\WINDOWS\system32\drivers\Avg
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Program Files\AVG
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-07-08 20:29 . 2008-07-10 11:37 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-08 20:29 . 2008-07-10 11:37 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-08 20:29 . 2008-07-10 11:37 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 14:53 . 2008-07-08 14:53 d——– C:\Program Files\Windows Media Connect 2
2008-07-08 14:53 . 2006-10-04 07:06 1,197,294 ——— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-07-08 14:53 . 2006-10-04 07:06 764,868 ——— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-07-08 14:53 . 2006-10-04 07:06 217,118 ——— C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\LogFiles
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\drivers\UMDF
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\fb7a99664bd1b57cb9ec4cac
2008-07-08 14:52 . 2008-06-13 06:10 272,128 –a—— C:\WINDOWS\system32\drivers\bthport.sys
2008-07-08 14:52 . 2008-06-13 06:10 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-08 14:46 . 2008-07-08 14:46 0 –a—— C:\WINDOWS\nsreg.dat
2008-07-08 14:31 . 2008-07-08 14:31 233,472 –a—— C:\WINDOWS\system32\wrap_oal.dll
2008-07-08 14:31 . 2008-07-08 14:31 81,920 –a—— C:\WINDOWS\system32\OpenAL32.dll
2008-07-08 14:20 . 2008-07-08 14:20 d——– C:\Program Files\MSN Messenger
2008-07-08 14:20 . 2008-07-08 14:55 d——– C:\Documents and Settings\Carl\Contacts
2008-07-08 14:20 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-07-08 14:18 . 2008-07-08 14:18 d——– C:\Documents and Settings\Carl\Application Data\CyberLink
2008-07-08 14:18 . 2004-08-03 23:08 26,496 –a—— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-08 14:18 . 2008-07-08 14:18 4,128 –a—— C:\INFCACHE.1
2008-07-08 14:16 . 2008-05-01 19:45 d——– C:\Documents and Settings\Carl\Application Data\InstallShield
2008-07-08 14:16 . 2008-07-17 17:34 d——– C:\Documents and Settings\Carl
2008-07-08 14:07 . 2004-08-03 20:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-07-08 14:07 . 2001-08-17 11:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-07-08 14:07 . 2001-08-17 12:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-07-08 14:07 . 2008-07-08 14:07 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-06-20 10:41 . 2008-06-20 10:41 245,248 ——— C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 03:44 . 2008-06-20 03:44 138,368 ——— C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 02:52 . 2008-06-20 02:52 225,920 ——— C:\WINDOWS\system32\dllcache\tcpip6.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 03:52 ——— d—–w C:\Program Files\Google
2008-07-10 19:07 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-09 04:29 ——— d—–w C:\Program Files\Java
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 19:47 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-13 17:21 142104]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-13 17:21 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-13 17:21 138008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 09:56 124200]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2008-02-28 10:59 17920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 01:06 40048]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 04:23 61440]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-10 11:37 1232152]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 18:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BearFlix\\bearflix.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-10 11:37]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-10 11:37]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-10 11:37]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-10 11:37]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DellSupportCenter - C:\Program Files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - C:\Program Files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-98f0b535 - C:\WINDOWS\system32\cwuhembh.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-17 21:08:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-07-17 21:09:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-18 04:09:47
Pre-Run: 241,161,850,880 bytes free
Post-Run: 241,169,084,416 bytes free
164 — E O F — 2008-07-16 10:00:45
and here is the second one…
ComboFix 08-07-15.4 - Carl 2008-07-17 21:39:49.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.504 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-17 21:12 . 2008-07-17 21:12 d——– C:\Program Files\Trend Micro
2008-07-17 20:59 . 2008-07-17 20:59 d——– C:\Program Files\Windows Live Safety Center
2008-07-16 19:28 . 2008-07-17 21:30 d——– C:\$AVG8.VAULT$
2008-07-16 18:07 . 2008-07-17 20:34 d——– C:\Documents and Settings\Carl\Application Data\TmpRecentIcons
2008-07-16 18:07 . 2008-07-16 15:29 147,456 –a—— C:\WINDOWS\agpqlrfm.exe
2008-07-15 16:10 . 2008-07-15 16:12 d——– C:\Program Files\BearFlix
2008-07-15 16:10 . 2008-07-17 17:32 d——– C:\My Downloads
2008-07-15 15:59 . 2008-07-15 17:35 d——– C:\Documents and Settings\Carl\Application Data\LimeWire
2008-07-15 12:19 . 2007-08-13 18:54 33,792 –a—— C:\WINDOWS\system32\dllcache\custsat.dll
2008-07-12 16:27 . 2008-07-12 16:27 d–hs—- C:\Documents and Settings\Carl\UserData
2008-07-12 15:57 . 2008-07-12 16:32 d——– C:\Documents and Settings\Carl\Application Data\Multi-Note
2008-07-12 12:14 . 2008-07-12 12:14 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-10 12:23 . 2008-07-10 12:23 d——– C:\Program Files\Alwil Software
2008-07-10 12:18 . 2008-05-01 19:45 d——– C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-10 12:18 . 2008-07-17 17:34 d——– C:\Documents and Settings\Administrator
2008-07-09 16:55 . 2008-07-17 21:08 d——– C:\MDT
2008-07-09 16:27 . 2008-07-09 16:27 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-09 03:02 . 2006-08-21 02:14 128,896 ——— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-07-09 03:02 . 2006-08-21 02:14 23,040 ——— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-07-09 03:02 . 2006-08-21 05:21 16,896 ——— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-07-08 21:30 . 2008-07-15 12:27 d——– C:\Documents and Settings\Carl\Application Data\OpenOffice.org2
2008-07-08 21:29 . 2008-07-08 21:29 d——– C:\Program Files\OpenOffice.org 2.4
2008-07-08 20:43 . 2008-07-10 12:19 d——– C:\Program Files\ThreatFire
2008-07-08 20:43 . 2008-07-08 20:43 d——– C:\Documents and Settings\All Users\Application Data\PC Tools
2008-07-08 20:43 . 2008-04-24 16:52 12,608 –a—— C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-07-08 20:29 . 2008-07-17 17:37 d——– C:\WINDOWS\system32\drivers\Avg
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Program Files\AVG
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-07-08 20:29 . 2008-07-10 11:37 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-08 20:29 . 2008-07-10 11:37 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-08 20:29 . 2008-07-10 11:37 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 14:53 . 2008-07-08 14:53 d——– C:\Program Files\Windows Media Connect 2
2008-07-08 14:53 . 2006-10-04 07:06 1,197,294 ——— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-07-08 14:53 . 2006-10-04 07:06 764,868 ——— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-07-08 14:53 . 2006-10-04 07:06 217,118 ——— C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\LogFiles
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\drivers\UMDF
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\fb7a99664bd1b57cb9ec4cac
2008-07-08 14:52 . 2008-06-13 06:10 272,128 –a—— C:\WINDOWS\system32\drivers\bthport.sys
2008-07-08 14:52 . 2008-06-13 06:10 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-08 14:46 . 2008-07-08 14:46 0 –a—— C:\WINDOWS\nsreg.dat
2008-07-08 14:31 . 2008-07-08 14:31 233,472 –a—— C:\WINDOWS\system32\wrap_oal.dll
2008-07-08 14:31 . 2008-07-08 14:31 81,920 –a—— C:\WINDOWS\system32\OpenAL32.dll
2008-07-08 14:20 . 2008-07-08 14:20 d——– C:\Program Files\MSN Messenger
2008-07-08 14:20 . 2008-07-08 14:55 d——– C:\Documents and Settings\Carl\Contacts
2008-07-08 14:20 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-07-08 14:18 . 2008-07-08 14:18 d——– C:\Documents and Settings\Carl\Application Data\CyberLink
2008-07-08 14:18 . 2004-08-03 23:08 26,496 –a—— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-08 14:18 . 2008-07-08 14:18 4,128 –a—— C:\INFCACHE.1
2008-07-08 14:16 . 2008-05-01 19:45 d——– C:\Documents and Settings\Carl\Application Data\InstallShield
2008-07-08 14:16 . 2008-07-17 17:34 d——– C:\Documents and Settings\Carl
2008-07-08 14:07 . 2004-08-03 20:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-07-08 14:07 . 2001-08-17 11:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-07-08 14:07 . 2001-08-17 12:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-07-08 14:07 . 2008-07-08 14:07 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-06-20 10:41 . 2008-06-20 10:41 245,248 ——— C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 03:44 . 2008-06-20 03:44 138,368 ——— C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 02:52 . 2008-06-20 02:52 225,920 ——— C:\WINDOWS\system32\dllcache\tcpip6.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 03:52 ——— d—–w C:\Program Files\Google
2008-07-10 19:07 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-09 04:29 ——— d—–w C:\Program Files\Java
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-05-08 12:28 202,752 ——w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-24 05:16 3,591,680 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-21 07:04 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-04-21 07:04 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-04-21 07:03 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2008-04-21 07:03 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2008-04-21 07:03 1,023,488 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2008-04-20 05:07 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((( snapshot@2008-07-17_21.09.36.85 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 19:47 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-13 17:21 142104]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-13 17:21 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-13 17:21 138008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 09:56 124200]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2008-02-28 10:59 17920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 01:06 40048]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 04:23 61440]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-10 11:37 1232152]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 18:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BearFlix\\bearflix.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-10 11:37]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-10 11:37]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-10 11:37]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-10 11:37]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-17 21:40:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\parent.lock
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\places.sqlite-journal
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\places.sqlite-stmtjrnl
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\sessionstore.js
C:\Documents and Settings\Carl\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_5898_F0D8_98F0_B59A\$db_clean$ 0 bytes
scan completed successfully
hidden files: 5
**************************************************************************
.
Completion time: 2008-07-17 21:41:08
ComboFix-quarantined-files.txt 2008-07-18 04:41:06
ComboFix2.txt 2008-07-18 04:09:51
Pre-Run: 241,170,898,944 bytes free
Post-Run: 241,161,404,416 bytes free
151 — E O F — 2008-07-16 10:00:45
ComboFix 08-07-15.4 - Carl 2008-07-17 21:03:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.596 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Carl\Favorites\Error Cleaner.url
C:\Documents and Settings\Carl\Favorites\Privacy Protector.url
C:\Documents and Settings\Carl\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\evgratsm.dll
C:\WINDOWS\ewkb.exe
C:\WINDOWS\kvxqmtre.dll
C:\WINDOWS\system32\aberzw.dll
C:\WINDOWS\system32\apmedfel.dll
C:\WINDOWS\system32\bbabLRqr.ini
C:\WINDOWS\system32\bbabLRqr.ini2
C:\WINDOWS\system32\cwuhembh.dll
C:\WINDOWS\system32\hbmehuwc.ini
C:\WINDOWS\system32\ljJDWNGA.dll
C:\WINDOWS\system32\mlJBTjhH.dll
C:\WINDOWS\system32\pdgqvqqb.dll
C:\WINDOWS\system32\rqRLbabb.dll
C:\WINDOWS\system32\vloxqb.dll
C:\WINDOWS\system32\x64
—– BITS: Possible infected sites —–
hxxp://www.dellsupportõj
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-17 20:59 . 2008-07-17 20:59 d——– C:\WINDOWS\LastGood.Tmp
2008-07-17 20:59 . 2008-07-17 20:59 d——– C:\Program Files\Windows Live Safety Center
2008-07-16 19:28 . 2008-07-16 19:28 d——– C:\$AVG8.VAULT$
2008-07-16 18:07 . 2008-07-17 20:34 d——– C:\Documents and Settings\Carl\Application Data\TmpRecentIcons
2008-07-16 18:07 . 2008-07-16 15:29 147,456 –a—— C:\WINDOWS\agpqlrfm.exe
2008-07-15 16:10 . 2008-07-15 16:12 d——– C:\Program Files\BearFlix
2008-07-15 16:10 . 2008-07-17 17:32 d——– C:\My Downloads
2008-07-15 15:59 . 2008-07-15 17:35 d——– C:\Documents and Settings\Carl\Application Data\LimeWire
2008-07-15 12:19 . 2007-08-13 18:54 33,792 –a—— C:\WINDOWS\system32\dllcache\custsat.dll
2008-07-12 16:27 . 2008-07-12 16:27 d–hs—- C:\Documents and Settings\Carl\UserData
2008-07-12 15:57 . 2008-07-12 16:32 d——– C:\Documents and Settings\Carl\Application Data\Multi-Note
2008-07-12 12:14 . 2008-07-12 12:14 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-10 12:23 . 2008-07-10 12:23 d——– C:\Program Files\Alwil Software
2008-07-10 12:18 . 2008-05-01 19:45 d——– C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-10 12:18 . 2008-07-17 17:34 d——– C:\Documents and Settings\Administrator
2008-07-09 16:55 . 2008-07-17 21:08 d——– C:\MDT
2008-07-09 16:27 . 2008-07-09 16:27 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-09 03:02 . 2006-08-21 02:14 128,896 ——— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-07-09 03:02 . 2006-08-21 02:14 23,040 ——— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-07-09 03:02 . 2006-08-21 05:21 16,896 ——— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-07-08 21:30 . 2008-07-15 12:27 d——– C:\Documents and Settings\Carl\Application Data\OpenOffice.org2
2008-07-08 21:29 . 2008-07-08 21:29 d——– C:\Program Files\OpenOffice.org 2.4
2008-07-08 20:43 . 2008-07-10 12:19 d——– C:\Program Files\ThreatFire
2008-07-08 20:43 . 2008-07-08 20:43 d——– C:\Documents and Settings\All Users\Application Data\PC Tools
2008-07-08 20:43 . 2008-04-24 16:52 12,608 –a—— C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-07-08 20:29 . 2008-07-17 17:37 d——– C:\WINDOWS\system32\drivers\Avg
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Program Files\AVG
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-07-08 20:29 . 2008-07-10 11:37 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-08 20:29 . 2008-07-10 11:37 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-08 20:29 . 2008-07-10 11:37 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 14:53 . 2008-07-08 14:53 d——– C:\Program Files\Windows Media Connect 2
2008-07-08 14:53 . 2006-10-04 07:06 1,197,294 ——— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-07-08 14:53 . 2006-10-04 07:06 764,868 ——— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-07-08 14:53 . 2006-10-04 07:06 217,118 ——— C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\LogFiles
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\drivers\UMDF
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\fb7a99664bd1b57cb9ec4cac
2008-07-08 14:52 . 2008-06-13 06:10 272,128 –a—— C:\WINDOWS\system32\drivers\bthport.sys
2008-07-08 14:52 . 2008-06-13 06:10 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-08 14:46 . 2008-07-08 14:46 0 –a—— C:\WINDOWS\nsreg.dat
2008-07-08 14:31 . 2008-07-08 14:31 233,472 –a—— C:\WINDOWS\system32\wrap_oal.dll
2008-07-08 14:31 . 2008-07-08 14:31 81,920 –a—— C:\WINDOWS\system32\OpenAL32.dll
2008-07-08 14:20 . 2008-07-08 14:20 d——– C:\Program Files\MSN Messenger
2008-07-08 14:20 . 2008-07-08 14:55 d——– C:\Documents and Settings\Carl\Contacts
2008-07-08 14:20 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-07-08 14:18 . 2008-07-08 14:18 d——– C:\Documents and Settings\Carl\Application Data\CyberLink
2008-07-08 14:18 . 2004-08-03 23:08 26,496 –a—— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-08 14:18 . 2008-07-08 14:18 4,128 –a—— C:\INFCACHE.1
2008-07-08 14:16 . 2008-05-01 19:45 d——– C:\Documents and Settings\Carl\Application Data\InstallShield
2008-07-08 14:16 . 2008-07-17 17:34 d——– C:\Documents and Settings\Carl
2008-07-08 14:07 . 2004-08-03 20:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-07-08 14:07 . 2001-08-17 11:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-07-08 14:07 . 2001-08-17 12:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-07-08 14:07 . 2008-07-08 14:07 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-06-20 10:41 . 2008-06-20 10:41 245,248 ——— C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 03:44 . 2008-06-20 03:44 138,368 ——— C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 02:52 . 2008-06-20 02:52 225,920 ——— C:\WINDOWS\system32\dllcache\tcpip6.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 03:52 ——— d—–w C:\Program Files\Google
2008-07-10 19:07 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-09 04:29 ——— d—–w C:\Program Files\Java
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 19:47 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-13 17:21 142104]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-13 17:21 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-13 17:21 138008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 09:56 124200]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2008-02-28 10:59 17920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 01:06 40048]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 04:23 61440]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-10 11:37 1232152]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 18:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BearFlix\\bearflix.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-10 11:37]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-10 11:37]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-10 11:37]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-10 11:37]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DellSupportCenter - C:\Program Files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - C:\Program Files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-98f0b535 - C:\WINDOWS\system32\cwuhembh.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-17 21:08:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-07-17 21:09:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-18 04:09:47
Pre-Run: 241,161,850,880 bytes free
Post-Run: 241,169,084,416 bytes free
164 — E O F — 2008-07-16 10:00:45
and here is the second one…
ComboFix 08-07-15.4 - Carl 2008-07-17 21:39:49.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.504 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-17 21:12 . 2008-07-17 21:12 d——– C:\Program Files\Trend Micro
2008-07-17 20:59 . 2008-07-17 20:59 d——– C:\Program Files\Windows Live Safety Center
2008-07-16 19:28 . 2008-07-17 21:30 d——– C:\$AVG8.VAULT$
2008-07-16 18:07 . 2008-07-17 20:34 d——– C:\Documents and Settings\Carl\Application Data\TmpRecentIcons
2008-07-16 18:07 . 2008-07-16 15:29 147,456 –a—— C:\WINDOWS\agpqlrfm.exe
2008-07-15 16:10 . 2008-07-15 16:12 d——– C:\Program Files\BearFlix
2008-07-15 16:10 . 2008-07-17 17:32 d——– C:\My Downloads
2008-07-15 15:59 . 2008-07-15 17:35 d——– C:\Documents and Settings\Carl\Application Data\LimeWire
2008-07-15 12:19 . 2007-08-13 18:54 33,792 –a—— C:\WINDOWS\system32\dllcache\custsat.dll
2008-07-12 16:27 . 2008-07-12 16:27 d–hs—- C:\Documents and Settings\Carl\UserData
2008-07-12 15:57 . 2008-07-12 16:32 d——– C:\Documents and Settings\Carl\Application Data\Multi-Note
2008-07-12 12:14 . 2008-07-12 12:14 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-10 12:23 . 2008-07-10 12:23 d——– C:\Program Files\Alwil Software
2008-07-10 12:18 . 2008-05-01 19:45 d——– C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-10 12:18 . 2008-07-17 17:34 d——– C:\Documents and Settings\Administrator
2008-07-09 16:55 . 2008-07-17 21:08 d——– C:\MDT
2008-07-09 16:27 . 2008-07-09 16:27 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-09 03:02 . 2006-08-21 02:14 128,896 ——— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-07-09 03:02 . 2006-08-21 02:14 23,040 ——— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-07-09 03:02 . 2006-08-21 05:21 16,896 ——— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-07-08 21:30 . 2008-07-15 12:27 d——– C:\Documents and Settings\Carl\Application Data\OpenOffice.org2
2008-07-08 21:29 . 2008-07-08 21:29 d——– C:\Program Files\OpenOffice.org 2.4
2008-07-08 20:43 . 2008-07-10 12:19 d——– C:\Program Files\ThreatFire
2008-07-08 20:43 . 2008-07-08 20:43 d——– C:\Documents and Settings\All Users\Application Data\PC Tools
2008-07-08 20:43 . 2008-04-24 16:52 12,608 –a—— C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-07-08 20:29 . 2008-07-17 17:37 d——– C:\WINDOWS\system32\drivers\Avg
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Program Files\AVG
2008-07-08 20:29 . 2008-07-08 20:29 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-07-08 20:29 . 2008-07-10 11:37 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-08 20:29 . 2008-07-10 11:37 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-08 20:29 . 2008-07-10 11:37 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 14:53 . 2008-07-08 14:53 d——– C:\Program Files\Windows Media Connect 2
2008-07-08 14:53 . 2006-10-04 07:06 1,197,294 ——— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-07-08 14:53 . 2006-10-04 07:06 764,868 ——— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-07-08 14:53 . 2006-10-04 07:06 217,118 ——— C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\LogFiles
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\WINDOWS\system32\drivers\UMDF
2008-07-08 14:52 . 2008-07-08 14:52 d——– C:\fb7a99664bd1b57cb9ec4cac
2008-07-08 14:52 . 2008-06-13 06:10 272,128 –a—— C:\WINDOWS\system32\drivers\bthport.sys
2008-07-08 14:52 . 2008-06-13 06:10 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-08 14:46 . 2008-07-08 14:46 0 –a—— C:\WINDOWS\nsreg.dat
2008-07-08 14:31 . 2008-07-08 14:31 233,472 –a—— C:\WINDOWS\system32\wrap_oal.dll
2008-07-08 14:31 . 2008-07-08 14:31 81,920 –a—— C:\WINDOWS\system32\OpenAL32.dll
2008-07-08 14:20 . 2008-07-08 14:20 d——– C:\Program Files\MSN Messenger
2008-07-08 14:20 . 2008-07-08 14:55 d——– C:\Documents and Settings\Carl\Contacts
2008-07-08 14:20 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-07-08 14:18 . 2008-07-08 14:18 d——– C:\Documents and Settings\Carl\Application Data\CyberLink
2008-07-08 14:18 . 2004-08-03 23:08 26,496 –a—— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-08 14:18 . 2008-07-08 14:18 4,128 –a—— C:\INFCACHE.1
2008-07-08 14:16 . 2008-05-01 19:45 d——– C:\Documents and Settings\Carl\Application Data\InstallShield
2008-07-08 14:16 . 2008-07-17 17:34 d——– C:\Documents and Settings\Carl
2008-07-08 14:07 . 2004-08-03 20:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-07-08 14:07 . 2001-08-17 11:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-07-08 14:07 . 2001-08-17 12:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-07-08 14:07 . 2008-07-08 14:07 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-06-20 10:41 . 2008-06-20 10:41 245,248 ——— C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 03:44 . 2008-06-20 03:44 138,368 ——— C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 02:52 . 2008-06-20 02:52 225,920 ——— C:\WINDOWS\system32\dllcache\tcpip6.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 03:52 ——— d—–w C:\Program Files\Google
2008-07-10 19:07 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-09 04:29 ——— d—–w C:\Program Files\Java
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-05-08 12:28 202,752 ——w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-24 05:16 3,591,680 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-21 07:04 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-04-21 07:04 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-04-21 07:03 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2008-04-21 07:03 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2008-04-21 07:03 1,023,488 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2008-04-20 05:07 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((( snapshot@2008-07-17_21.09.36.85 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 19:47 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-13 17:21 142104]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-13 17:21 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-13 17:21 138008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 09:56 124200]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2008-02-28 10:59 17920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 01:06 40048]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 04:23 61440]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-10 11:37 1232152]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 18:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BearFlix\\bearflix.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-10 11:37]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-10 11:37]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-10 11:37]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-10 11:37]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-17 21:40:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\parent.lock
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\places.sqlite-journal
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\places.sqlite-stmtjrnl
C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\dzs3226r.default\sessionstore.js
C:\Documents and Settings\Carl\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_5898_F0D8_98F0_B59A\$db_clean$ 0 bytes
scan completed successfully
hidden files: 5
**************************************************************************
.
Completion time: 2008-07-17 21:41:08
ComboFix-quarantined-files.txt 2008-07-18 04:41:06
ComboFix2.txt 2008-07-18 04:09:51
Pre-Run: 241,170,898,944 bytes free
Post-Run: 241,161,404,416 bytes free
151 — E O F — 2008-07-16 10:00:45