ComboFix 09-12-09.04 - Brett 10/12/2009 22:32:05.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.702.247 [GMT 0:00]
Running from: c:documents and settingsBrettdesktopcommy.exe
Command switches used :: /stepdel
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:documents and settingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr0.dat
c:documents and settingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr1.dat
c:documents and settingsBrettLocal SettingsApplication Databndegd
c:documents and settingsBrettLocal SettingsApplication Databndegdjvubsysguard.exe
c:windowssystem32uninstall.exe
----- BITS: Possible infected sites -----
hxxp://sync.broadband.o2.co.uk:8080.
((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 )))))))))))))))))))))))))))))))
.
2009-12-10 22:24 . 2009-12-10 22:24 -------- d-----w- C:FOUND.006
2009-12-10 20:45 . 2009-12-10 20:45 -------- d-----w- c:documents and settingsBrettLocal SettingsApplication DataDownloaded Installations
2009-12-10 20:44 . 2009-12-10 20:44 -------- d-----w- c:documents and settingsAll UsersApplication DataRegCure
2009-12-10 20:44 . 2009-12-10 20:44 -------- d-----w- c:program filesRegCure
2009-12-10 20:44 . 2009-12-03 16:14 38224 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2009-12-10 20:44 . 2009-12-10 20:44 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes
2009-12-10 20:44 . 2009-12-03 16:13 19160 ----a-w- c:windowssystem32driversmbam.sys
2009-12-10 20:43 . 2009-12-10 20:44 -------- d-----w- c:program filesMalwarebytes' Anti-Malware
2009-12-10 20:32 . 2009-10-30 11:11 233136 ----a-w- c:windowssystem32driverspctgntdi.sys
2009-12-10 20:32 . 2009-11-09 11:20 207792 ----a-w- c:windowssystem32driversPCTCore.sys
2009-12-10 20:32 . 2009-10-06 16:31 87784 ----a-w- c:windowssystem32driversPCTAppEvent.sys
2009-12-10 20:32 . 2009-09-03 09:45 70408 ----a-w- c:windowssystem32driverspctplsg.sys
2009-12-10 20:32 . 2009-12-10 20:32 -------- d-----w- c:program filesSpyware Doctor
2009-12-10 20:32 . 2009-12-10 20:32 -------- d-----w- c:program filesCommon FilesPC Tools
2009-12-10 20:32 . 2009-12-10 20:32 -------- d-----w- c:documents and settingsBrettApplication DataPC Tools
2009-12-10 20:32 . 2009-12-10 20:32 -------- d-----w- c:documents and settingsAll UsersApplication DataPC Tools
2009-12-10 20:31 . 2009-12-10 20:31 -------- d-----w- c:documents and settingsAll UsersApplication DataTEMP
2009-12-10 20:02 . 2009-12-10 20:02 -------- d-----w- C:FOUND.005
2009-12-09 19:57 . 2009-12-09 19:57 -------- d-----w- c:documents and settingsBrettApplication DataSkyGolf
2009-11-22 22:48 . 2009-11-22 22:48 -------- d-----w- c:documents and settingsBrettApplication DataAVS4YOU
2009-11-22 22:48 . 2009-11-22 22:48 -------- d-----w- c:documents and settingsAll UsersApplication DataAVS4YOU
2009-11-22 22:45 . 2009-11-22 22:45 -------- d-----w- c:program filesCommon FilesAVSMedia
2009-11-22 22:45 . 2008-08-13 10:22 974848 ----a-w- c:windowssystem32mfc70.dll
2009-11-22 22:45 . 2008-08-13 10:22 487424 ----a-w- c:windowssystem32msvcp70.dll
2009-11-22 22:45 . 2009-11-22 22:45 -------- d-----w- c:program filesAVS4YOU
2009-11-22 22:45 . 2008-08-13 10:22 344064 ----a-w- c:windowssystem32msvcr70.dll
2009-11-22 22:45 . 2008-08-13 10:22 24576 ----a-w- c:windowssystem32msxml3a.dll
2009-11-16 22:09 . 2009-11-16 22:09 -------- d-----w- C:FOUND.004
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 09:04 . 2007-03-02 08:39 40800 ----a-w- c:documents and settingsBrettLocal SettingsApplication DataGDIPFONTCACHEV1.DAT
2009-11-06 09:02 . 2009-11-06 09:02 -------- d-----w- c:program filesMicrosoft
2009-11-06 09:02 . 2009-11-06 09:02 -------- d-----w- c:program filesWindows Live SkyDrive
2009-10-29 07:45 . 2006-01-09 11:08 916480 ----a-w- c:windowssystem32wininet.dll
2009-10-21 05:38 . 2004-08-04 05:00 75776 ----a-w- c:windowssystem32strmfilt.dll
2009-10-21 05:38 . 2004-08-04 05:00 25088 ----a-w- c:windowssystem32httpapi.dll
2009-10-20 16:20 . 2004-08-04 05:00 265728 ----a-w- c:windowssystem32drivershttp.sys
2009-10-18 19:35 . 2009-10-18 19:35 152576 ----a-w- c:documents and settingsBrettApplication DataSunJavajre1.6.0_15lzma.dll
2009-10-18 19:34 . 2009-10-18 19:34 -------- d-----w- c:program filesCCleaner
2009-10-18 16:25 . 2009-10-18 16:25 14 ----a-w- c:windowssystem32Systemdrv.sys
2009-10-13 10:30 . 2004-08-04 05:00 270336 ----a-w- c:windowssystem32oakley.dll
2009-10-12 13:38 . 2004-08-04 05:00 149504 ----a-w- c:windowssystem32rastls.dll
2009-10-12 13:38 . 2004-08-04 05:00 79872 ----a-w- c:windowssystem32raschap.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"MsnMsgr"="c:program filesWindows LiveMessengerMsnMsgr.Exe" [2009-07-26 3883856]
"c:program filesNetMeterNetMeter.exe"="c:program filesNetMeterNetMeter.exe" [2007-08-11 331264]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"eDataSecurity Loader"="c:acerEmpowering TechnologyeDataSecurityeDSloader.exe 1" [X]
"PCSuiteTrayApplication"="c:program filesNokiaNokia PC Suite 6LaunchApplication.exe -startup" [X]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-16 16248320]
"SkyTel"="SkyTel.EXE" [2006-08-16 2879488]
"AzMixerSel"="c:program filesRealtekInstallShieldAzMixerSel.exe" [2006-08-16 53248]
"IMJPMIG8.1"="c:windowsIMEimjp8_1IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:windowssystem32IMEPINTLGNTImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:windowssystem32IMETINTLGNTTINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:windowssystem32IMETINTLGNTTINTSETP.EXE" [2004-08-04 455168]
"SynTPEnh"="c:program filesSynapticsSynTPSynTPEnh.exe" [2006-08-15 766041]
"ATICCC"="c:program filesATI TechnologiesATI.ACECLIStart.exe" [2006-05-10 90112]
"LManager"="c:progra~1LAUNCH~1QtZgAcer.EXE" [2006-09-07 479232]
"eRecoveryService"="c:acerEmpowering TechnologyeRecoveryeRAgent.exe" [2006-06-01 413696]
"AVG8_TRAY"="c:progra~1AVGAVG8avgtray.exe" [2009-11-27 2029336]
"LogitechCommunicationsManager"="c:program filesCommon FilesLogiShrdLComMgrCommunications_Helper.exe" [2006-12-22 497176]
"LogitechQuickCamRibbon"="c:program filesLogitechQuickCam10QuickCam10.exe" [2006-12-22 756248]
"CaddieSyncLauncher"="c:program filesSkyGolfSkyCaddie DesktopCaddieSyncLauncher.exe" [2009-10-22 95744]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"PcSync"="c:program filesNokiaNokia PC Suite 6PcSync2.exe" [2006-11-09 1634304]
c:documents and settingsBrettStart MenuProgramsStartup
LimeWire On Startup.lnk - c:program filesLimeWireLimeWire.exe [2009-9-30 503808]
c:documents and settingsAll UsersStart MenuProgramsStartup
Adobe Reader Speed Launch.lnk - c:program filesAdobeAcrobat 7.0Readerreader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:program filesMicrosoft OfficeOffice10OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogonnotifyavgrsstarter]
2009-08-30 09:04 11952 ----a-w- c:windowssystem32avgrsstx.dll
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"c:\Program Files\Messenger\msmsgs.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\Program Files\AVG\AVG8\avgupd.exe"=
"c:\Program Files\LimeWire\LimeWire.exe"=
"c:\Program Files\O2\agent\bin\bcont.exe"=
"c:\Program Files\O2\bin\wificfg.exe"=
"c:\Program Files\Common Files\SupportSoft\bin\ssrc.exe"=
"c:\Program Files\O2\agent\bin\bcont_nm.exe"=
"c:\Program Files\Windows Live\Messenger\wlcsdk.exe"=
"c:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"c:\Program Files\Skype\Phone\Skype.exe"=
"c:\Program Files\SkyGolf\SkyCaddie Desktop\SkyCaddieDesktop.exe"=
R0 PCTCore;PCTools KDS;c:windowssystem32driversPCTCore.sys [10/12/2009 8:32 p.m. 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:windowssystem32driversavgldx86.sys [5/08/2008 10:29 p.m. 335240]
R2 avg8wd;AVG Free8 WatchDog;c:progra~1AVGAVG8avgwdsvc.exe [8/02/2009 9:57 a.m. 297752]
R2 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:program filesO2binsprtsvc.exe [4/03/2009 3:52 p.m. 202016]
S3 KS-959;Kingsun KS-959 USB Infrared Adapter;c:windowssystem32driversKS-959.sys [13/04/2007 4:35 p.m. 19018]
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.pga.co.nz/uInternet Connection Wizard,ShellNext =
hxxp://en.nz.acer.yahoo.com/uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://au.rd.yahoo.com/customize/ycomp/defaults/su/*http://au.yahoo.com
Trusted Zone: o2.co.uk*.broadband
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-wpncffgs - c:documents and settingsBrettLocal SettingsApplication Databndegdjvubsysguard.exe
HKLM-Run-LaunchApp - (no file)
HKLM-Run-wpncffgs - c:documents and settingsBrettLocal SettingsApplication Databndegdjvubsysguard.exe
AddRemove-GoldWave v5.19 - c:documents and settingsBrettDesktopJunkGoldWaveunstall.exe
AddRemove-SLABCOMM - c:windowssystem32uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-10 22:37
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERSS-1-5-21-3006582075-3980647206-3948150123-1006SoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved{A1FAEBDA-0910-F862-8FA6-C81D2EF7F181}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(544)
c:windowssystem32Ati2evxx.dll
.
Completion time: 2009-12-10 22:38:30
ComboFix-quarantined-files.txt 2009-12-10 22:38
Pre-Run: 5,771,984,896 bytes free
Post-Run: 6,018,088,960 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)WINDOWS
[operating systems]
c:cmdconsBOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - 27B9DD5F388DDD85E59DA1DAF607EDDE