tmroberts80
OK. This time it did open a log for me. Sorry for the confusion. I didn't delete nearly as many files this time, but that's probably good. Worked the 1st time.
ComboFix 08-12-18.01 - toby 2008-12-19 13:42:11.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.194 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\test.txt
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\toby\Cookies\icum.scr
c:\documents and settings\toby\Cookies\pyvywy.vbs
c:\documents and settings\toby\Cookies\tygikij.reg
c:\documents and settings\toby\Cookies\uger.lib
c:\documents and settings\toby\Local Settings\Temporary Internet Files\eryze.dll
c:\documents and settings\toby\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\tinyproxy\tinyproxy.exe
C:\test.txt
c:\windows\system32\mlJcBTjh.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_EVENT_LOG_(EVENTLOG)_
——-\Legacy_NETWORK_CONNECTIONS_(NETMAN)_
——-\Service_Event Log (Eventlog)
——-\Service_Network Connections (Netman)
((((((((((((((((((((((((( Files Created from 2008-11-19 to 2008-12-19 )))))))))))))))))))))))))))))))
.
2008-12-19 03:12 . 2008-12-19 03:12 d——– c:\windows\LastGood
2008-12-17 22:09 . 2008-12-17 22:19 d——– c:\documents and settings\toby\Application Data\uTorrent
2008-12-17 19:53 . 2008-12-17 19:53 d——– C:\_OTScanIt
2008-12-14 21:48 . 2008-12-14 21:48 d——– c:\program files\Trend Micro
2008-12-14 21:06 . 2008-12-14 21:35 d——– c:\documents and settings\Administrator
2008-12-11 15:20 . 2008-12-14 21:35 d——– c:\documents and settings\Guest
2008-12-05 14:04 . 2008-12-05 14:08 d——– c:\program files\Spybot - Search & Destroy
2008-12-05 14:04 . 2008-12-09 03:28 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-27 16:36 . 2008-11-27 16:36 d——– c:\program files\iPod
2008-11-27 16:35 . 2008-11-27 16:36 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-27 16:33 . 2008-11-27 16:33 d——– c:\program files\Bonjour
2008-11-27 16:32 . 2008-11-27 16:33 d——– c:\program files\QuickTime
2008-11-27 16:27 . 2008-11-27 16:36 d——– c:\program files\Common Files\Apple
2008-11-27 16:27 . 2008-11-27 16:27 d——– c:\documents and settings\All Users\Application Data\Apple
2008-11-25 01:59 . 2008-11-25 01:59 d——– c:\program files\uTorrent
2008-11-24 14:23 . 2008-12-09 18:20 d——– c:\program files\a-squared Anti-Malware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 04:26 96,256 —-a-w c:\windows\system32\drivers\sptd7949.sys
2008-12-15 05:43 3,853 —-a-w c:\program files\hijackthis.log
2008-12-13 18:16 ——— d—–w c:\program files\backups
2008-12-09 11:36 ——— d—–w c:\documents and settings\Yoshi\Application Data\uTorrent
2008-12-01 22:09 ——— d—–w c:\program files\DivX
2008-11-28 00:36 ——— d—–w c:\program files\iTunes
2008-11-28 00:29 ——— d—–w c:\program files\Apple Software Update
2008-11-09 21:11 ——— d—–w c:\documents and settings\toby\Application Data\Wizards of the Coast
2008-11-09 20:49 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-09 20:49 ——— d—–w c:\program files\Wizards of the Coast
2008-11-09 20:48 ——— d—–w c:\documents and settings\toby\Application Data\InstallShield
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 22:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 10:20 667,648 —-a-w c:\windows\system32\wininet.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-01 00:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-19 21:55 200,704 —-a-w c:\windows\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 —-a-w c:\windows\system32\libdivx.dll
2005-02-16 19:06 218,112 —-a-w c:\program files\HijackThis.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-03-30 5898240]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"midi1"= xgusb.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Yoshi\\Desktop\\utorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-07-14 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-14 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-14 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-07-14 76040]
R2 WUSB300NSvc;WUSB300NSvc;"c:\program files\Linksys\WUSB300N\WLService.exe" "WUSB300N.exe" [2007-10-11 53307]
S2 MioNet;MioNet Service;"c:\program files\MioNet\MioNetManager.exe" -s "c:\program files\MioNet\wrapper.conf" []
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\DRIVERS\gflmouhid.sys [2004-04-19 6656]
S3 IPN2120;Instant Wireless-B PCI Adapter Driver;c:\windows\system32\DRIVERS\LSIPNDS.sys []
S3 ISD200;USB Storage Adapter V2;c:\windows\system32\DRIVERS\ISD200.SYS [2006-03-24 26930]
.
Contents of the 'Scheduled Tasks' folder
2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-RRT-Auto - c:\documents and settings\toby\Desktop\RRT.exe
MSConfigStartUp-HostManager - c:\program files\Common Files\AOL\1140765838\ee\AOLSoftware.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
FF - ProfilePath - c:\documents and settings\toby\Application Data\Mozilla\Firefox\Profiles\jzaymth3.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np32dsw.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppl3260.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-19 13:46:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-19 13:48:40
ComboFix-quarantined-files.txt 2008-12-19 21:48:31
Pre-Run: 54,306,480,128 bytes free
Post-Run: 54,292,303,872 bytes free
189 — E O F — 2008-12-19 11:03:20
ComboFix 08-12-18.01 - toby 2008-12-19 13:42:11.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.194 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\test.txt
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\toby\Cookies\icum.scr
c:\documents and settings\toby\Cookies\pyvywy.vbs
c:\documents and settings\toby\Cookies\tygikij.reg
c:\documents and settings\toby\Cookies\uger.lib
c:\documents and settings\toby\Local Settings\Temporary Internet Files\eryze.dll
c:\documents and settings\toby\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\tinyproxy\tinyproxy.exe
C:\test.txt
c:\windows\system32\mlJcBTjh.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_EVENT_LOG_(EVENTLOG)_
——-\Legacy_NETWORK_CONNECTIONS_(NETMAN)_
——-\Service_Event Log (Eventlog)
——-\Service_Network Connections (Netman)
((((((((((((((((((((((((( Files Created from 2008-11-19 to 2008-12-19 )))))))))))))))))))))))))))))))
.
2008-12-19 03:12 . 2008-12-19 03:12 d——– c:\windows\LastGood
2008-12-17 22:09 . 2008-12-17 22:19 d——– c:\documents and settings\toby\Application Data\uTorrent
2008-12-17 19:53 . 2008-12-17 19:53 d——– C:\_OTScanIt
2008-12-14 21:48 . 2008-12-14 21:48 d——– c:\program files\Trend Micro
2008-12-14 21:06 . 2008-12-14 21:35 d——– c:\documents and settings\Administrator
2008-12-11 15:20 . 2008-12-14 21:35 d——– c:\documents and settings\Guest
2008-12-05 14:04 . 2008-12-05 14:08 d——– c:\program files\Spybot - Search & Destroy
2008-12-05 14:04 . 2008-12-09 03:28 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-27 16:36 . 2008-11-27 16:36 d——– c:\program files\iPod
2008-11-27 16:35 . 2008-11-27 16:36 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-27 16:33 . 2008-11-27 16:33 d——– c:\program files\Bonjour
2008-11-27 16:32 . 2008-11-27 16:33 d——– c:\program files\QuickTime
2008-11-27 16:27 . 2008-11-27 16:36 d——– c:\program files\Common Files\Apple
2008-11-27 16:27 . 2008-11-27 16:27 d——– c:\documents and settings\All Users\Application Data\Apple
2008-11-25 01:59 . 2008-11-25 01:59 d——– c:\program files\uTorrent
2008-11-24 14:23 . 2008-12-09 18:20 d——– c:\program files\a-squared Anti-Malware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 04:26 96,256 —-a-w c:\windows\system32\drivers\sptd7949.sys
2008-12-15 05:43 3,853 —-a-w c:\program files\hijackthis.log
2008-12-13 18:16 ——— d—–w c:\program files\backups
2008-12-09 11:36 ——— d—–w c:\documents and settings\Yoshi\Application Data\uTorrent
2008-12-01 22:09 ——— d—–w c:\program files\DivX
2008-11-28 00:36 ——— d—–w c:\program files\iTunes
2008-11-28 00:29 ——— d—–w c:\program files\Apple Software Update
2008-11-09 21:11 ——— d—–w c:\documents and settings\toby\Application Data\Wizards of the Coast
2008-11-09 20:49 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-09 20:49 ——— d—–w c:\program files\Wizards of the Coast
2008-11-09 20:48 ——— d—–w c:\documents and settings\toby\Application Data\InstallShield
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 22:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 10:20 667,648 —-a-w c:\windows\system32\wininet.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-01 00:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-19 21:55 200,704 —-a-w c:\windows\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 —-a-w c:\windows\system32\libdivx.dll
2005-02-16 19:06 218,112 —-a-w c:\program files\HijackThis.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-03-30 5898240]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"midi1"= xgusb.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Yoshi\\Desktop\\utorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-07-14 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-14 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-14 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-07-14 76040]
R2 WUSB300NSvc;WUSB300NSvc;"c:\program files\Linksys\WUSB300N\WLService.exe" "WUSB300N.exe" [2007-10-11 53307]
S2 MioNet;MioNet Service;"c:\program files\MioNet\MioNetManager.exe" -s "c:\program files\MioNet\wrapper.conf" []
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\DRIVERS\gflmouhid.sys [2004-04-19 6656]
S3 IPN2120;Instant Wireless-B PCI Adapter Driver;c:\windows\system32\DRIVERS\LSIPNDS.sys []
S3 ISD200;USB Storage Adapter V2;c:\windows\system32\DRIVERS\ISD200.SYS [2006-03-24 26930]
.
Contents of the 'Scheduled Tasks' folder
2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-RRT-Auto - c:\documents and settings\toby\Desktop\RRT.exe
MSConfigStartUp-HostManager - c:\program files\Common Files\AOL\1140765838\ee\AOLSoftware.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
FF - ProfilePath - c:\documents and settings\toby\Application Data\Mozilla\Firefox\Profiles\jzaymth3.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np32dsw.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppl3260.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-19 13:46:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-19 13:48:40
ComboFix-quarantined-files.txt 2008-12-19 21:48:31
Pre-Run: 54,306,480,128 bytes free
Post-Run: 54,292,303,872 bytes free
189 — E O F — 2008-12-19 11:03:20