ComboFix 09-06-18.02 - Compaq_Administrator 06/18/2009 17:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1982.1553 [GMT -7:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Manson
c:\program files\Manson\liser.dll
c:\program files\Manson\liser.exe
c:\windows\IE4 Error Log.txt
c:\windows\kb913800.exe
c:\windows\system32\drivers\UACyiurqrrnmqfwosd.sys
c:\windows\system32\UACbnrpulpwhiamigc.dll
c:\windows\system32\UACeyrqoxevdajgsmr.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiummygbmaivmvwq.log
c:\windows\system32\UACorjasqtxwujklvv.dll
c:\windows\system32\UACotewpkbuoesoxvk.dat
c:\windows\system32\UACpqgpuevytvneuee.log
c:\windows\system32\UACqjkhximkrsmyoll.dll
c:\windows\system32\UACrwtnbgixdlxwbpj.dll
c:\windows\system32\uactmp.db
c:\windows\system32\UACuxjvymnnjfboapq.dll
c:\windows\system32\UACvpyxfddnaevlabn.db
c:\windows\system32\UACyjbbpxnwuphhqbd.dll
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-05-19 to 2009-06-19 )))))))))))))))))))))))))))))))
.
2009-06-18 23:51 . 2009-06-18 23:51 -------- d-----w- c:\program files\Trend Micro
2009-06-18 21:57 . 2009-06-18 21:57 578560 ----a-w- c:\windows\system32\dllcache\user32.dll
2009-06-18 21:47 . 2009-06-18 21:48 -------- d-----w- c:\windows\ERUNT
2009-06-18 19:01 . 2009-06-18 19:05 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-18 15:41 . 2009-06-18 12:52 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-18 15:41 . 2009-06-18 12:52 2052376 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-18 15:40 . 2009-06-18 12:52 27784 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmfx86.sys
2009-06-18 15:40 . 2009-06-18 12:52 352024 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-06-18 15:40 . 2009-06-18 12:52 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-18 15:40 . 2009-06-18 12:52 1261344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-18 15:40 . 2009-06-18 12:52 1452312 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-18 14:48 . 2009-06-17 18:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-18 14:48 . 2009-06-18 23:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-18 14:48 . 2009-06-18 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-18 14:48 . 2009-06-17 18:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-18 13:43 . 2009-06-18 13:43 -------- d-----w- c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\AVG Security Toolbar
2009-06-18 13:03 . 2009-06-02 20:37 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-18 12:52 . 2009-06-18 12:52 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-18 12:52 . 2009-06-18 12:52 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-18 12:52 . 2009-06-18 12:52 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-18 12:52 . 2009-06-18 15:32 -------- d-----w- c:\windows\system32\drivers\Avg
2009-06-18 12:52 . 2009-06-18 12:52 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-18 12:52 . 2009-06-18 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-18 12:52 . 2009-06-18 12:52 -------- d-----w- c:\program files\AVG
2009-06-18 12:22 . 2009-06-18 12:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-18 12:22 . 2009-06-18 12:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-18 12:15 . 2009-06-18 21:30 -------- d-----w- c:\documents and settings\All Users\Application Data\93755456
2009-06-18 12:15 . 2009-06-18 21:30 -------- d-----w- c:\documents and settings\All Users\Application Data\13745464
2009-05-29 04:37 . 2008-11-20 19:19 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-05-29 04:37 . 2008-11-20 19:19 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-05-29 04:32 . 2009-05-29 04:32 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-05-21 17:09 . 2009-06-12 07:24 -------- d-----w- c:\program files\MyRegistryCleaner
2009-05-21 17:08 . 2009-05-21 17:09 -------- d-----w- c:\documents and settings\Compaq_Administrator\Application Data\GetRightToGo
2009-05-21 17:02 . 2009-05-21 17:02 -------- d-----w- c:\documents and settings\Compaq_Administrator\Application Data\Uniblue
2009-05-21 16:52 . 2009-05-21 16:52 -------- d-----w- c:\program files\PopCap Games
2009-05-21 16:52 . 2009-05-21 16:52 0 ----a-w- c:\windows\popcreg.dat
2009-05-21 16:52 . 2009-05-21 16:52 0 ----a-w- c:\windows\popcinfot.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-18 23:05 . 2007-04-03 23:30 -------- d-----w- c:\program files\BitLord
2009-06-18 15:51 . 2006-01-16 20:17 115224 ----a-w- c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-18 15:40 . 2007-07-23 23:57 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-29 04:32 . 2005-11-11 21:41 -------- d-----w- c:\program files\Google
2009-05-07 15:32 . 2004-08-10 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-29 04:56 . 2004-08-10 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-10 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 21:04 . 2006-03-08 08:49 96384 ----a-w- c:\windows\system32\drivers\sptd1677.sys
2009-04-15 14:51 . 2004-08-10 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-15 00:42 . 2005-01-28 17:40 92947 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-15 00:42 . 2009-04-15 00:42 61440 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2009-04-15 00:42 . 2009-04-15 00:42 45056 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2009-04-15 00:42 . 2009-04-15 00:42 44032 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2009-04-15 00:42 . 2009-04-15 00:42 40960 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2009-04-15 00:42 . 2009-04-15 00:42 341048 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2009-04-15 00:42 . 2009-04-15 00:42 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2009-04-15 00:42 . 2009-04-15 00:42 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2009-04-15 00:42 . 2009-04-15 00:42 163840 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 20:37 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-18 12:52 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^E3TV Tray App.lnk]
path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\E3TV Tray App.lnk
backup=c:\windows\pss\E3TV Tray App.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^The Matrix_ Path of Neo Registration.lnk]
path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\The Matrix_ Path of Neo Registration.lnk
backup=c:\windows\pss\The Matrix_ Path of Neo Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"freenet-darknet-8888"=3 (0x3)
"avg8wd"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1137892249\\ee\\aolsoftware.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Documents and Settings\\Compaq_Administrator\\My Documents\\World of Warcraft\\WoW-2.4.3-to-3.0.2-enUS-Win-Final-downloader.exe"=
"c:\\Documents and Settings\\Compaq_Administrator\\My Documents\\World of Warcraft\\BackgroundDownloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Compaq_Administrator\\Desktop\\Downloads\\Age of Empires\\empires2.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
"c:\\Program Files\\Common Files\\AOL\\1137892249\\ee\\aim6.exe"=
"c:\\Documents and Settings\\Compaq_Administrator\\My Documents\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\VentSrv\\ventrilo_srv.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2009 5:52 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2009 5:52 AM 108552]
S3 ATIXPGAA;ATIXPGAA;\??\c:\program files\PC-Doctor 5 for Windows\ATIXPGAA.SYS --> c:\program files\PC-Doctor 5 for Windows\ATIXPGAA.SYS [?]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/18/2009 5:52 AM 298776]
S4 freenet-darknet-8888;Freenet 0.7 darknet-8888;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2009-06-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 22:57]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktopuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8mSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktopuInternet Connection Wizard,ShellNext =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktopIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-18 18:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-06-19 18:01
ComboFix-quarantined-files.txt 2009-06-19 01:01
Pre-Run: 123,561,631,744 bytes free
Post-Run: 124,139,151,360 bytes free
197 --- E O F --- 2009-06-12 21:02