ComboFix 09-06-12.02 - Administrator 06/12/2009 16:23.2 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.3039 [GMT -5:00]
Running from: d:\downloads\Combo-Fix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Viewpoint
c:\program files\Manson
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Service_Viewpoint Manager Service
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-12 17:12 . 2009-06-12 17:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG8
2009-06-05 04:51 . 2009-06-05 04:51 -------- d-----w- c:\program files\iPod
2009-06-05 04:51 . 2009-06-05 04:52 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-05 04:51 . 2009-06-05 04:51 -------- d-----w- c:\program files\Bonjour
2009-06-05 04:51 . 2009-06-05 04:51 -------- d-----w- c:\program files\QuickTime
2009-06-05 04:49 . 2009-05-29 18:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 04:46 . 2009-06-05 04:46 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-23 17:07 . 2009-05-23 17:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-20 03:08 . 2008-10-10 09:52 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-05-20 03:08 . 2008-10-10 09:52 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-05-20 03:08 . 2008-10-27 15:04 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2009-05-20 03:08 . 2008-07-30 11:20 238088 ----a-w- c:\windows\system32\xactengine3_2.dll
2009-05-20 03:08 . 2008-07-10 16:01 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2009-05-20 03:08 . 2008-07-10 16:00 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 20:41 . 2008-10-07 01:15 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-12 17:28 . 2009-06-12 17:28 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-06-12 17:28 . 2009-06-12 17:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-12 17:28 . 2009-06-12 17:28 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-12 17:28 . 2009-06-12 17:28 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-12 17:28 . 2009-06-12 17:28 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 17:28 . 2009-06-12 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-12 17:28 . 2009-06-12 17:28 -------- d-----w- c:\program files\AVG
2009-06-12 17:28 . 2009-06-12 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-05 04:50 . 2008-09-30 17:47 -------- d-----w- c:\program files\Common Files\Apple
2009-06-05 04:49 . 2008-09-30 17:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-05 04:21 . 2008-09-30 17:48 -------- d-----w- c:\documents and settings\Admin\Application Data\Apple Computer
2009-05-29 18:36 . 2008-09-30 17:47 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-19 06:36 . 2009-06-10 11:28 2884832 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\vwpt.exe
2009-05-19 06:36 . 2009-06-10 11:28 28 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\unregister.bat
2009-05-19 06:36 . 2009-06-10 11:28 25 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\register.bat
2009-05-19 06:36 . 2009-06-10 11:28 1484856 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\toolbar.exe
2009-05-19 06:36 . 2009-06-10 11:28 97072 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\bsetutil.exe
2009-05-19 06:36 . 2009-06-10 11:28 142040 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\alsetup.exe
2009-05-19 06:36 . 2009-06-10 11:28 30512 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\Uninstaller.exe
2009-05-19 06:36 . 2009-06-10 11:28 111920 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\AOLSearch.dll
2009-05-07 15:32 . 2003-03-31 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2003-03-31 12:00 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll
2009-04-27 09:22 . 2009-04-27 09:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2009-04-26 17:38 . 2009-04-26 17:38 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-04-24 18:09 . 2009-04-24 18:09 -------- d-----w- c:\documents and settings\Admin\Application Data\Macrovision
2009-04-23 22:09 . 2009-04-23 22:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2009-04-17 12:26 . 2003-03-31 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2003-03-31 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-03-20 16:54 . 2008-09-30 20:49 62378 ----a-w- c:\windows\War3Unin.dat
2009-03-19 21:32 . 2009-03-19 21:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 21:32 . 2008-09-30 17:48 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-09-30 16:41 . 2008-09-30 16:41 15083520 ----a-w- c:\program files\spybotsd160.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 18:38 1004800 ----a-w- d:\avg\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"Ai Nap"="c:\program files\ASUS\Ai Suite\AiNap\AiNap.exe" [2007-09-06 1426432]
"CPU Power Monitor"="c:\program files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe" [2007-09-07 626688]
"Cpu Level Up help"="c:\program files\ASUS\Ai Suite\CpuLevelUpHelp.exe" [2007-09-11 880640]
"Launch LGDCore"="c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 1126400]
"SunJavaUpdateSched"="d:\java\jre6\bin\jusched.exe" [2009-02-12 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-29 185872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2009-05-30 292136]
"AVG8_TRAY"="d:\avg\AVG8\avgtray.exe" [2009-06-12 1948440]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2005-07-23 28160]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-17 1657376]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - d:\logitech\SetPoint\SetPoint.exe [2008-9-30 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-12 17:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Warcraft III\\Listchecker\\pickup.listchecker.exe"=
"d:\\Warcraft III\\war3.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Red Alert3\\Data\\ra3_1.4.game"=
"d:\\Steam\\steamapps\\ledzeppelin16@hotmail.com\\counter-strike source\\hl2.exe"=
"d:\\Hamachi\\hamachi.exe"=
"d:\\Ventrilo\\Ventrilo.exe"=
"d:\\Red Alert3\\Data\\ra3_1.5.game"=
"d:\\Red Alert3\\Data\\ra3_1.6.game"=
"d:\\Steam\\Steam.exe"=
"d:\\F.E.A.R. 2 SP Demo\\FEAR2SPDemo.exe"=
"d:\\Steam\\steamapps\\ledzeppelin16@hotmail.com\\team fortress 2\\hl2.exe"=
"c:\\ijji\\ENGLISH\\u_gbound.exe"=
"d:\\Gunbound\\ENGLISH\\Gunbound Revolution\\GunBound.gme"=
"d:\\Steam\\steamapps\\common\\tom clancy's h.a.w.x - demo\\HAWX.exe"=
"d:\\Steam\\steamapps\\ledzeppelin16@hotmail.com\\insurgency\\hl2.exe"=
"d:\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"d:\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"d:\\World of Warcraft\\Launcher.exe"=
"d:\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"d:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"d:\\Steam\\steamapps\\common\\battlestations pacific - demo\\bspdemo.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\iTunes\\iTunes.exe"=
"d:\\AVG\\AVG8\\avgam.exe"=
"d:\\AVG\\AVG8\\avgdiag.exe"=
"d:\\AVG\\AVG8\\avgdiagex.exe"=
"d:\\AVG\\AVG8\\avgupd.exe"=
"d:\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [6/12/2009 12:28 PM 12552]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/12/2009 12:28 PM 108552]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/12/2009 12:28 PM 327688]
S2 avg8wd;AVG8 WatchDog;d:\avg\AVG8\avgwdsvc.exe [6/12/2009 12:28 PM 298776]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 4:10 PM 32512]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-12 16:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9F9DEBB-68B5-F470-73ABBBDFE6B7698C}\{2DE0854A-58E2-477C-18CA38B62B72F56E}\{B78F9583-EE49-B075-5FB6B2640AC6C572}*]
"XOGCPEUPGZA3BTOUPKIJ6FJXTE1"=hex:01,00,01,00,00,00,00,00,9a,27,1e,8a,da,80,81,
12,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
------------------------ Other Running Processes ------------------------
.
d:\lavasoft\Ad-Aware\aawservice.exe
.
**************************************************************************
.
Completion time: 2009-06-12 16:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-12 21:28
ComboFix2.txt 2009-06-12 21:05
Pre-Run: 4,573,454,336 bytes free
Post-Run: 4,564,738,048 bytes free
180 --- E O F --- 2009-06-11 08:01