ComboFix 09-02-02.04 - User 2009-02-02 19:36:48.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.544 [GMT -5:00]
Running from: c:\documents and settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.
2009-01-29 19:30 . 2009-01-29 20:16 d——– c:\documents and settings\User\Application Data\mjusbsp
2009-01-29 19:29 . 2008-04-13 14:45 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-01-29 19:29 . 2008-04-13 14:45 60,032 –a–c— c:\windows\system32\dllcache\usbaudio.sys
2009-01-29 19:28 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2009-01-29 19:28 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2009-01-28 02:00 . 2009-01-28 02:00 d——– c:\documents and settings\User\LocalLow
2009-01-28 02:00 . 2009-01-28 02:00 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2009-01-15 02:15 . 2009-01-15 02:15 d——– C:\61df232c486c6796dd2d
2009-01-15 01:29 . 2009-01-15 01:29 0 –a—— c:\windows\nsreg.dat
2009-01-07 05:20 . 2009-01-07 05:20 d——– c:\program files\Microsoft Games
2009-01-07 05:16 . 2009-01-07 05:16 d——– c:\program files\Alawar
2009-01-06 00:44 . 2009-01-06 00:45 d——– c:\documents and settings\User\Application Data\ErrorFix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-02 14:11 ——— d—–w c:\program files\Common
2009-01-27 22:16 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-27 22:16 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-27 22:16 ——— d—–w c:\documents and settings\All Users\Application Data\Avg8
2009-01-15 06:43 ——— d—–w c:\documents and settings\User\Application Data\Move Networks
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-06 10:22 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-17 14:43 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101720081018\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-16 1164912]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-16 1941784]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-16 87584]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2008-02-13 2065648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-25 136600]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"VTTimer"="VTTimer.exe" [2006-09-21 c:\windows\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2006-10-09 c:\windows\system32\S3Trayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 c:\windows\RTHDCPL.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-01-08 114688]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-20 65588]
Microsoft Works Calendar Reminders.lnk - c:\windows\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe [2008-01-08 30720]
Watch.lnk - c:\program files\DV Series\Console\Watch.exe [2008-09-29 217088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-27 17:16 10520 c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-25 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-10-25 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-10-25 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-25 298264]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2008-01-03 634880]
S3 BFAIFILT;BFAIFILT;c:\windows\system32\drivers\BFAIFILT.SYS [2008-01-12 3264]
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service;c:\windows\system32\drivers\U2KG54.SYS [2008-01-12 245376]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fd03ae00-ee64-11dd-b0c2-001d92410860}]
\Shell\AutoRun\command - E:\autorun.exe
\Shell\phone\command - E:\autorun.exe
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\569f1s9h.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-02 19:39:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(792)
c:\windows\system32\relog_ap.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\snmp.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-02 19:41:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-03 00:41:25
ComboFix2.txt 2008-10-26 01:59:30
Pre-Run: 70,652,272,640 bytes free
Post-Run: 70,789,476,352 bytes free
Current=2 Default=2 Failed=4 LastKnownGood=1 Sets=1,2,3,4
122 — E O F — 2009-01-15 19:12:11
oops, i did that wrong….
try again:
ComboFix 09-02-02.04 - User 2009-02-02 19:36:48.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.544 [GMT -5:00]
Running from: c:\documents and settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.
2009-01-29 19:30 . 2009-01-29 20:16 d——– c:\documents and settings\User\Application Data\mjusbsp
2009-01-29 19:29 . 2008-04-13 14:45 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-01-29 19:29 . 2008-04-13 14:45 60,032 –a–c— c:\windows\system32\dllcache\usbaudio.sys
2009-01-29 19:28 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2009-01-29 19:28 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2009-01-28 02:00 . 2009-01-28 02:00 d——– c:\documents and settings\User\LocalLow
2009-01-28 02:00 . 2009-01-28 02:00 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2009-01-15 02:15 . 2009-01-15 02:15 d——– C:\61df232c486c6796dd2d
2009-01-15 01:29 . 2009-01-15 01:29 0 –a—— c:\windows\nsreg.dat
2009-01-07 05:20 . 2009-01-07 05:20 d——– c:\program files\Microsoft Games
2009-01-07 05:16 . 2009-01-07 05:16 d——– c:\program files\Alawar
2009-01-06 00:44 . 2009-01-06 00:45 d——– c:\documents and settings\User\Application Data\ErrorFix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-02 14:11 ——— d—–w c:\program files\Common
2009-01-27 22:16 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-27 22:16 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-27 22:16 ——— d—–w c:\documents and settings\All Users\Application Data\Avg8
2009-01-15 06:43 ——— d—–w c:\documents and settings\User\Application Data\Move Networks
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-06 10:22 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-17 14:43 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101720081018\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-16 1164912]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-16 1941784]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-16 87584]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2008-02-13 2065648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-25 136600]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"VTTimer"="VTTimer.exe" [2006-09-21 c:\windows\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2006-10-09 c:\windows\system32\S3Trayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 c:\windows\RTHDCPL.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-01-08 114688]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-20 65588]
Microsoft Works Calendar Reminders.lnk - c:\windows\Installer\{0CD3BB5C-BBCA-11D2-8C20-00C04FBBCFF9}\A94AAB13.exe [2008-01-08 30720]
Watch.lnk - c:\program files\DV Series\Console\Watch.exe [2008-09-29 217088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-27 17:16 10520 c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-25 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-10-25 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-10-25 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-25 298264]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2008-01-03 634880]
S3 BFAIFILT;BFAIFILT;c:\windows\system32\drivers\BFAIFILT.SYS [2008-01-12 3264]
S3 U2KG54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service;c:\windows\system32\drivers\U2KG54.SYS [2008-01-12 245376]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fd03ae00-ee64-11dd-b0c2-001d92410860}]
\Shell\AutoRun\command - E:\autorun.exe
\Shell\phone\command - E:\autorun.exe
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\569f1s9h.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-02 19:39:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(792)
c:\windows\system32\relog_ap.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\snmp.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-02 19:41:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-03 00:41:25
ComboFix2.txt 2008-10-26 01:59:30
Pre-Run: 70,652,272,640 bytes free
Post-Run: 70,789,476,352 bytes free
Current=2 Default=2 Failed=4 LastKnownGood=1 Sets=1,2,3,4
122 — E O F — 2009-01-15 19:12:11
oh….maybe not, looks the same
is this what you needed?????