ComboFix 08-03-18.1 - daves account 2008-03-20 3:33:00.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.214 [GMT 0:00]
Running from: C:\Documents and Settings\daves account\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\popcorn Terms.html
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.
2008-03-19 22:05 . 2008-03-19 22:05 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-19 22:05 . 2008-03-19 02:50 <DIR> d-------- C:\SDFix
2008-03-19 17:20 . 2008-03-19 17:20 <DIR> d-------- C:\Documents and Settings\daves account\Contacts
2008-03-19 17:18 . 2008-03-19 17:18 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-03-19 16:59 . 2008-03-19 16:59 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-19 16:28 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-19 16:28 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-19 16:28 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-19 15:29 . 2008-03-19 15:39 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-19 15:28 . 2008-03-19 17:17 <DIR> d-------- C:\Program Files\Windows Live
2008-03-19 15:28 . 2008-03-19 17:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-19 12:42 . 2005-05-27 10:10 121,425 --a------ C:\temp\aol9clearlocsUtil.exe
2008-03-19 12:41 . 2008-03-19 12:41 <DIR> d-------- C:\Program Files\Common Files\FTL Shared
2008-03-19 12:40 . 2008-03-19 12:40 <DIR> d-------- C:\Program Files\BT Voyager 105 ADSL Modem
2008-03-19 12:40 . 2004-03-24 17:53 160,951 --------- C:\WINDOWS\system32\drivers\gtipdsp_.bin
2008-03-19 12:40 . 2003-08-15 12:56 138,402 --a------ C:\WINDOWS\system32\drivers\glausb.sys
2008-03-19 12:40 . 2003-08-15 14:51 24,576 --a------ C:\WINDOWS\system32\CoInst.dll
2008-03-19 12:40 . 2004-03-26 17:41 17,020 --------- C:\WINDOWS\wwdslcfg.ini
2008-03-19 12:40 . 2003-06-10 14:55 12,288 --------- C:\WINDOWS\system32\CplEng.dll
2008-03-19 12:35 . 2008-03-19 12:39 <DIR> d-------- C:\Program Files\VoyagerModem105Drivers
2008-03-19 12:35 . 2008-03-19 12:35 1,409 --a------ C:\WINDOWS\system32\tmpB2601.FOT
2008-03-19 12:35 . 2008-03-19 12:35 1,409 --a------ C:\WINDOWS\system32\tmpA6601.FOT
2008-03-19 12:35 . 2008-03-19 12:35 1,409 --a------ C:\WINDOWS\system32\tmp8A601.FOT
2008-03-19 12:35 . 2008-03-19 12:35 1,409 --a------ C:\WINDOWS\system32\tmp7E601.FOT
2008-03-18 19:44 . 2008-03-18 19:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-18 07:19 . 2008-03-18 07:19 <DIR> d-------- C:\Program Files\Auslogics
2008-03-18 07:19 . 2008-03-18 07:19 <DIR> d-------- C:\Documents and Settings\daves account\Application Data\Auslogics
2008-03-18 07:17 . 2008-03-19 21:05 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-18 07:17 . 2008-03-18 07:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-18 07:16 . 2008-03-18 07:16 <DIR> d-------- C:\Program Files\Apple Software Update
2008-03-18 07:16 . 2008-03-18 07:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-03-18 06:11 . 2008-03-18 06:11 <DIR> d-------- C:\Program Files\VS Revo Group
2008-03-18 05:44 . 2008-03-18 05:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-18 05:41 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-18 05:20 . 2008-03-18 05:20 <DIR> d-------- C:\Program Files\IObit
2008-03-18 05:15 . 2008-03-18 20:54 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-18 05:15 . 2008-03-18 05:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-18 05:15 . 2008-03-18 05:15 <DIR> d-------- C:\Documents and Settings\daves account\Application Data\SUPERAntiSpyware.com
2008-03-18 05:15 . 2008-03-18 05:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-18 05:09 . 2008-03-18 05:09 <DIR> d-------- C:\Program Files\CCleaner
2008-03-18 05:03 . 2008-03-18 05:03 <DIR> d-------- C:\Program Files\CleanUp!
2008-03-14 08:05 . 2008-03-14 08:05 <DIR> d-------- C:\Documents and Settings\daves account\Application Data\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-03-19 12:41 --------- d-----w C:\Program Files\VoyagerTest
2008-03-18 18:31 --------- d-----w C:\Program Files\fsupport
2008-03-18 15:19 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-18 07:18 --------- d-----w C:\Program Files\QuickTime
2008-03-18 07:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-18 06:44 --------- d-----w C:\Program Files\Common Files\AOL
2008-03-18 06:42 --------- d-----w C:\Program Files\AOL 9.0
2008-03-18 06:08 --------- d-----w C:\Program Files\Common Files\Real
2008-03-18 06:07 --------- d-----w C:\Program Files\Common Files\Labtec
2008-03-18 06:04 --------- d-----w C:\Program Files\Easy Internet signup
2008-03-18 05:56 --------- d-----w C:\Documents and Settings\daves account\Application Data\AVG7
2008-03-18 05:48 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-18 05:41 --------- d-----w C:\Program Files\Java
2008-03-14 08:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2004-11-01 00:14 56 -csh--r C:\WINDOWS\system32\B41C55C019.sys
2004-11-01 00:14 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Acme.PCHButton"="C:\PROGRA~1\PRESAR~1\Presario\XP HWWRS4\plugin\bin\PCHButton.exe" [2004-01-02 00:59 159744]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 11:01 88209 C:\WINDOWS\AGRSMMSG.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-31 08:57 579072]
"HostManager"="C:\Program Files\Common Files\AOL\1175764236\ee\AOLSoftware.exe" [2006-11-17 13:21 50736]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-02-23 21:43 3026944]
"DSLSTATEXE"="C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe" [2003-06-28 15:10 1658965]
"DSLAGENTEXE"="C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe" [2003-08-19 12:47 16384]
"%FP%Friendly fts.exe"="C:\Program Files\VoyagerTest\fts.exe" [2003-05-06 09:28 72192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-13 08:59 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\AOL 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2007-12-07 15:30 71008 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMBROWSEMOUSE]
C:\Program Files\Trust\302KS\Mouse\mouse32a.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-02-23 15:45 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Common Files\\AOL\\1175764236\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 lanusb;GlobeSpan USB ADSL LAN Modem;C:\WINDOWS\system32\DRIVERS\glausb.sys [2003-08-15 12:56]
R3 PPPoEWin;PPPoEWin Miniport;C:\WINDOWS\system32\DRIVERS\PPPoEWin.SYS [2003-09-25 16:52]
S3 jbridgep;jbridgep;C:\DOCUME~1\Owner\LOCALS~1\Temp\ jbridgep.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480
*Newly Created Service* - ATWPKT2
.
Contents of the 'Scheduled Tasks' folder
"2008-03-18 22:01:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-20 03:34:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-03-20 3:34:48
ComboFix-quarantined-files.txt 2008-03-20 03:34:33
.
2008-03-20 03:02:23 --- E O F ---