ComboFix 10-11-22.04 - Admin 11/22/2010 18:26:36.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.478.186 [GMT -7:00]
Running from: E:\combo-fix.exe
Command switches used :: E:\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Admin\LOCALS~1\Temp\jna7411195242135381786.dll
c:\documents and settings\Admin\Local Settings\Temp\jna7411195242135381786.dll
.
((((((((((((((((((((((((( Files Created from 2010-10-23 to 2010-11-23 )))))))))))))))))))))))))))))))
.
2010-11-21 03:53 . 2010-11-21 03:53 -------- d-----w- c:\documents and settings\All Users\Application Data\T-Mobile
2010-11-21 03:50 . 2010-11-21 03:50 -------- d-----w- c:\documents and settings\Admin\Application Data\MSNInstaller
2010-11-21 00:17 . 2010-11-21 00:17 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\PackageAware
2010-11-20 22:44 . 2010-11-20 22:44 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2010-11-20 22:44 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-20 22:44 . 2010-11-20 22:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-20 22:44 . 2010-11-20 22:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-20 22:44 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-20 21:59 . 2010-11-20 21:59 -------- d--h--w- c:\windows\PIF
2010-11-20 20:07 . 2010-11-20 20:17 -------- d-----w- c:\documents and settings\Admin\Application Data\GetRightToGo
2010-11-20 08:04 . 2010-11-20 08:04 105984 --sha-r- c:\windows\system32\rtutilsh.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((
SnapShot@2010-11-22_21.51.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-23 01:33 . 2010-11-23 01:33 16384 c:\windows\Temp\Perflib_Perfdata_794.dat
+ 2006-12-04 19:38 . 2006-12-04 19:38 53248 c:\windows\inf\WG511v2\snetcfg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeper.exe" [2005-01-06 3552256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-06-17 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-06-17 118784]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-05 688218]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-09-17 290816]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-04-07 496752]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2007-11-02 26112]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-10-14 229438]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
c:\documents and settings\Admin\Start Menu\Programs\Startup\
DesktopVideoPlayer.LNK - c:\program files\vghd\vghd.exe [2009-2-21 600904]
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-3-10 503808]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG511v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG511v2\WG511v2.exe [2007-6-26 1499136]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
.
Contents of the 'Scheduled Tasks' folder
2010-10-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2008-02-17 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-08-13 21:58]
2010-11-22 c:\windows\Tasks\User_Feed_Synchronization-{97C9DE83-BE45-4951-829E-8AC1625FF1F0}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 10:05]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.bing.com/.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-11-22 18:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?5?5?4??p???? ???B?????????????H
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2664)
c:\windows\system32\SynTPFcs.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\vghd\VirtuaGirl_Downloader.exe
.
**************************************************************************
.
Completion time: 2010-11-22 18:40:16 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-23 01:40
ComboFix2.txt 2010-11-22 21:57
Pre-Run: 65,832,607,744 bytes free
Post-Run: 65,815,924,736 bytes free
- - End Of File - - C1B385F9C90175CD0017344E3DB48DAE