Thanks for your help!!
ComboFix 08-12-01.01 - meredith 2008-12-01 22:51:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.198 [GMT -5:00]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\LocalService\Application Data\NetMon
c:\documents and settings\LocalService\Application Data\NetMon\domains.txt
c:\documents and settings\LocalService\Application Data\NetMon\log.txt
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\ip3picfile.temp
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\ip3Wmapic.temp
c:\documents and settings\meredith\Application Data\gadcom
c:\documents and settings\meredith\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\meredith\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\inetget2
c:\program files\Mjcore
c:\program files\Mozilla Firefox\components\iamfamous.dll
c:\program files\network monitor
C:\resycled
c:\resycled\boot.com
c:\windows\SysNotifier.exe
c:\windows\system32\awtrQHxX.dll
c:\windows\system32\bbivcrxy.dll
c:\windows\system32\bioperlw.ini
c:\windows\system32\drivers\fad.sys
c:\windows\system32\drivers\TDSSpxst.sys
c:\windows\system32\efcaYstS.dll
c:\windows\system32\enmkdshs.dll
c:\windows\system32\eqnlxhhr.dll
c:\windows\system32\geBqOghI.dll
c:\windows\system32\kdebg.exe
c:\windows\system32\mcpcqs.dll
c:\windows\system32\shsdkmne.ini
c:\windows\system32\TDSSarxx.dll
c:\windows\system32\TDSSdxcp.dll
c:\windows\system32\TDSSkkao.log
c:\windows\system32\TDSSmtve.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnvuo.dll
c:\windows\system32\TDSSoitu.dll
c:\windows\system32\TDSSsahw.dll
c:\windows\system32\TDSSvoqm.dll
c:\windows\system32\TDSSxhyf.log
c:\windows\system32\vuazzw.dll
c:\windows\SYSTEM32\wGjTuBeg.ini
c:\windows\SYSTEM32\wGjTuBeg.ini2
c:\windows\uninstall_nmon.vbs
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS
——-\Legacy_CMDSERVICE
——-\Legacy_NETWORK_MONITOR
——-\Service_Network Monitor
((((((((((((((((((((((((( Files Created from 2008-11-02 to 2008-12-02 )))))))))))))))))))))))))))))))
.
2008-11-30 20:57 . 2008-11-30 20:57 d——– c:\program files\Audacity
2008-11-30 20:43 . 2008-04-13 14:45 60,032 –a—— c:\windows\SYSTEM32\DRIVERS\USBAUDIO.sys
2008-11-30 20:43 . 2008-04-13 14:45 60,032 –a—— c:\windows\SYSTEM32\DLLCACHE\usbaudio.sys
2008-11-30 20:19 . 2008-11-30 20:19 d——– c:\program files\ERUNT
2008-11-25 02:35 . 2008-11-25 15:43 d——– c:\documents and settings\meredith\Application Data\Twain
2008-11-25 02:30 . 2008-11-25 15:43 d——– c:\program files\Webtools
2008-11-23 22:55 . 2008-06-13 10:30 177,522 –a—— c:\windows\SYSTEM32\mediatab.swf
2008-11-23 22:55 . 2008-06-13 10:30 4,058 –a—— c:\windows\SYSTEM32\dls.swf
2008-11-23 22:25 . 2008-11-23 22:25 d——– c:\documents and settings\meredith\Application Data\IUpd721
2008-11-23 22:13 . 2008-11-25 15:01 d——– c:\documents and settings\meredith\Application Data\NI.GSCNS
2008-11-23 22:05 . 2008-11-23 22:05 29,184 –a—— c:\windows\SYSTEM32\MSINET.oca
2008-11-23 22:05 . 2008-11-23 22:05 2,407 –a—— c:\windows\SYSTEM32\MSINET.DEP
2008-11-23 21:52 . 2008-11-23 21:52 27,904 –a—— c:\windows\SYSTEM32\DRIVERS\ndisprot.sys
2008-11-23 21:06 . 2008-11-23 21:14 50 –a—— c:\windows\MegaManager.INI
2008-11-23 21:05 . 2008-11-23 21:06 d——– c:\documents and settings\meredith\Application Data\EmailNotifier
2008-11-23 21:05 . 2008-11-23 21:05 d——– c:\documents and settings\All Users\Application Data\Megaupload
2008-11-23 21:05 . 2008-11-23 21:05 d——– c:\documents and settings\All Users\Application Data\EmailNotifier
2008-11-21 09:39 . 2008-11-21 09:39 d——– c:\program files\Apple Software Update
2008-11-13 19:42 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-11-13 19:42 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 21:28 ——— d—–w c:\program files\SpywareBlaster
2008-11-25 20:43 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-11-25 20:40 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 16:14 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-11-24 02:15 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-10 03:53 26,148 —-a-w c:\documents and settings\meredith\Application Data\wklnhst.dat
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-05 21:38 ——— d—–w c:\documents and settings\meredith\Application Data\ESRI
2008-10-02 03:59 96,424 —-a-w c:\documents and settings\meredith\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2004-07-01 131072]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
c:\documents and settings\meredith\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2004-07-29 225280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-03-11 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll vuazzw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\btdownloadgui.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BearShare\\BearShare.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-05-25 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-05 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-05 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-05-25 76040]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-08-09 24652]
S3 Ndisprot;ArcNet NDIS Protocol Driver;\??\c:\windows\system32\drivers\Ndisprot.sys [2008-11-23 27904]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19cd689a-8023-11dc-9f24-000d56826c83}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fd03526-493d-11dc-9f07-00038a000015}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com e:
\Shell\Open\command - e:\resycled\boot.com e:
.
Contents of the 'Scheduled Tasks' folder
2008-11-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2004-03-17 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2008-04-13 19:12]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKLM-Run-c:\windows\system32\kdebg.exe - c:\windows\system32\kdebg.exe
Notify-iwnnet - c:\windows\system32\USMT\iwnnet.dll
Notify-efcDSiJy - efcDSiJy.dll
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\meredith\Application Data\Mozilla\Firefox\Profiles\ay6h9aav.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.msn.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-01 22:59:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-12-01 23:10:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-02 04:10:00
Pre-Run: 49,409,691,648 bytes free
Post-Run: 49,301,233,664 bytes free
185 — E O F — 2008-11-14 01:43:18
_______________________________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:57 PM, on 12/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Documents and Settings\meredith\Desktop\Anti-virus\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: avgrsstx.dll vuazzw.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 4297 bytes