ComboFix 08-01-02.1 - Owner 2008-01-03 10:02:28.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.436 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\7PR49H8X\www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\HP\KBD\KBD.EXE
C:\n.bat
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\{38F6A~1
c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Mattel\Barbie Girls\Mattel.BarbieGirls.Tray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Yahoo!\YOP\yop.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Temp
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\cEeer12\skAt.log
C:\temp\tn3
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\awtqo.dll.bad
C:\VundoFix Backups\awtqo.exe.bad
C:\VundoFix Backups\hkcmd.exe.bad
C:\VundoFix Backups\hphmon05.exe.bad
C:\VundoFix Backups\hpsysdrv.exe.bad
C:\VundoFix Backups\igfxtray.exe.bad
C:\VundoFix Backups\ljjjkll.dll.bad
C:\VundoFix Backups\msconfig.exe.bad
C:\VundoFix Backups\oqtwa.ini.bad
C:\VundoFix Backups\oqtwa.ini2.bad
C:\VundoFix Backups\ps2.exe.bad
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\Fonts\Crack.exe
C:\WINDOWS\QTFont.for
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\SMINST\RECGUARD.EXE
C:\WINDOWS\system32\aj2
C:\WINDOWS\system32\ardCo18
C:\WINDOWS\system32\ardCo18\ardCo182328.exe
C:\WINDOWS\system32\awtqo.dll
C:\WINDOWS\system32\awtqo.exe
C:\WINDOWS\system32\cc9
C:\WINDOWS\system32\components
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\edeeg.bak1
C:\WINDOWS\System32\flcss.exe
C:\WINDOWS\system32\kjllm.bak1
C:\WINDOWS\system32\kjllm.bak2
C:\WINDOWS\system32\ljjjkll.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mr9
C:\WINDOWS\system32\oqtwa.ini
C:\WINDOWS\system32\oqtwa.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\plyodmp.dll
C:\WINDOWS\system32\pp1
C:\WINDOWS\system32\RCX4B.tmp
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\system32\z1
C:\winlogon.exe
C:\x.dat
C:\z.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_COM+_MESSAGES
-------\LEGACY_CORE
-------\core
((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.
2008-01-02 22:14 . 2008-01-02 22:14 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-02 22:14 . 2008-01-02 22:14 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-02 22:14 . 2008-01-02 22:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-02 19:39 . 2008-01-01 01:17 158,208 --a--c--- C:\WINDOWS\system32\dllcache\msconfig.exe
2008-01-02 17:41 . 2008-01-02 17:41 <DIR> d-------- C:\Program Files\AOL Search
2008-01-01 15:51 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-30 16:59 . 2007-12-30 16:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-29 18:45 . 2007-12-29 18:45 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\acccore
2007-12-29 18:43 . 2008-01-02 17:42 <DIR> d-------- C:\Program Files\AIM6
2007-12-28 23:44 . 2006-08-21 03:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-12-28 23:44 . 2006-08-21 03:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2007-12-28 23:44 . 2006-08-21 06:21 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2007-12-28 23:22 . 2007-12-28 23:22 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-28 18:49 . 2008-01-01 12:16 182 --a------ C:\WINDOWS\system\hpsysdrv .DAT
2007-12-28 17:00 . 2007-12-28 17:00 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-12-28 16:48 . 2007-12-28 18:57 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 08:19 . 2007-07-09 07:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-12-27 23:37 . 2007-12-27 23:37 <DIR> d-------- C:\WINDOWS\provisioning
2007-12-27 23:37 . 2007-12-27 23:37 <DIR> d-------- C:\WINDOWS\peernet
2007-12-27 23:30 . 2007-12-27 23:30 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-12-27 23:14 . 2007-12-27 23:14 <DIR> d-------- C:\WINDOWS\EHome
2007-12-25 13:50 . 2007-12-25 13:50 <DIR> d-------- C:\Program Files\Mattel
2007-12-25 13:50 . 2007-12-25 13:50 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Mattel
2007-12-04 11:23 . 2007-12-04 23:16 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-04 11:23 . 2007-12-04 23:16 88 -r-hs---- C:\WINDOWS\system32\B12A0F95F1.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-03 03:59 --------- d-----w C:\Program Files\Yahoo!
2008-01-03 03:59 --------- d-----w C:\Program Files\Common Files\Scanner
2008-01-03 03:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-01-03 03:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-03 03:55 --------- d-----w C:\Program Files\Java
2008-01-02 21:59 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-01-02 21:59 --------- d-----w C:\Program Files\Multimedia Card Reader
2008-01-02 21:59 --------- d-----w C:\Program Files\iTunes
2008-01-02 21:57 --------- d-----w C:\Program Files\QuickTime
2008-01-01 18:15 --------- d-----w C:\Program Files\Trend Micro
2008-01-01 07:17 158,208 ----a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\msconfig.exe
2007-12-30 23:54 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-30 00:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-28 23:00 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2007-12-28 23:00 --------- d-----w C:\Documents and Settings\Owner\Application Data\FrostWire
2007-12-28 01:49 5,923,843 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-25 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-30 01:36 --------- d-----w C:\Documents and Settings\Owner\Application Data\Yahoo!
2007-11-17 02:26 --------- d-----w C:\Documents and Settings\Owner\Application Data\Apple Computer
2007-11-17 02:25 --------- d-----w C:\Program Files\iPod
2007-11-17 02:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-17 02:23 --------- d-----w C:\Program Files\Apple Software Update
2007-11-17 02:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-14 20:32 --------- d-----w C:\Program Files\FrostWire
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2006-12-20 17:15 103,327 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_12_19_11_24_30_small.dmp.zip
2006-10-30 16:26 98,508 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_10_28_11_48_20_small.dmp.zip
2006-10-19 03:39 132,534 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_10_18_12_41_12_small.dmp.zip
.
(((((((((((((((((((((((((((((
snapshot@2008-01-02_16.06.00.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-30 00:43:58 38,428 ----a-w C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
+ 2008-01-02 23:40:32 38,428 ----a-w C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
+ 2005-05-24 18:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 21:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 21:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-01-03 04:07:25 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_5d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22}]
2007-12-18 13:27 111968 --a------ C:\Program Files\AOL Search\AOLSearch.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"BackupNotify"="c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [2008-01-01 15:14 32768]
"Yahoo! Pager"="1" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-01-01 15:15 1318912]
"Window Washer"="C:\Program Files\Webroot\Washer\wwDisp.exe" [2008-01-01 15:15 1261384]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-12-18 13:04 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [ ]
"KBD"="C:\HP\KBD\KBD.EXE" [2008-01-01 15:14 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2008-01-01 15:14 221184]
"VTTimer"="VTTimer.exe" []
"LTMSG"="LTMSG.exe" [2003-07-14 19:52 40960 C:\WINDOWS\ltmsg.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [ ]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2008-01-01 15:14 135168]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-01-01 15:14 968696]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [ ]
"PRISMSVR.EXE"="C:\WINDOWS\System32\PRISMSVR.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-01-01 15:14 79224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-01 15:14 40048]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 02:15:54]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2007-05-10 12:08 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk
backup=C:\WINDOWS\pss\AT&T Self Support Tool.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=C:\WINDOWS\pss\spamsubtract.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
C:\Program Files\AIM6\aim6.exe /d locale=en-US ee://aol/imApp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BarbieGirlsTray]
2007-12-30 02:10 24576 --a------ C:\Program Files\Mattel\Barbie Girls\Mattel.BarbieGirls.Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaAvTray]
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAVRID]
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
2003-08-21 05:23 49152 --a------ c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2003-07-14 13:30 98304 --a------ C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-12-30 02:10 267048 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
2007-12-30 23:01 380928 --a------ C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 03:50 155648 --------- C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 03:50 155648 --------- C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
2008-01-01 15:01 57344 --a------ C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2001-12-20 10:00]
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-08-09 13:56]
S4 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2002-02-08 04:16]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 14:49:17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-03 10:06:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-03 10:07:47
ComboFix-quarantined-files.txt 2008-01-03 16:07:30
.
2007-12-30 19:00:27 --- E O F ---