Notes: not sure if its related, but my internet has been acting very strange, going from very fast to VERY VERY slow.
ComboFix 08-01-29.3 - MC Anthrax 2008-01-29 16:15:53.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.611 [GMT 11:00]
Running from: C:\Documents and Settings\MC Anthrax\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\WINDOWS\system32\guard32.dll
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-28 09:43 . 2008-01-28 09:43 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-28 09:43 . 2003-03-19 07:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-01-28 08:08 . 2008-01-28 08:08 <DIR> d-------- C:\Program Files\COMODO
2008-01-28 08:08 . 2008-01-28 08:08 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Application Data\Comodo
2008-01-28 08:08 . 2008-01-28 11:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-01-28 08:08 . 2008-01-28 08:08 139,008 --a------ C:\WINDOWS\system32\guard32.dll.vir
2008-01-28 08:08 . 2008-01-28 08:08 81,272 --a------ C:\WINDOWS\system32\drivers\cmdGuard.sys
2008-01-28 08:08 . 2008-01-28 08:08 23,672 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-01-27 12:19 . 2008-01-27 12:19 <DIR> d-------- C:\Documents and Settings\MC Anthrax\DefaultClasses
2008-01-27 12:18 . 2008-01-27 12:19 <DIR> d-------- C:\Documents and Settings\MC Anthrax\DefaultScripts
2008-01-27 09:19 . 2008-01-27 09:21 <DIR> d-------- C:\Program Files\BitLord
2008-01-27 08:11 . 2008-01-27 08:11 <DIR> d-------- C:\WINDOWS\vbSkinner
2008-01-27 08:09 . 2008-01-27 08:11 <DIR> d-------- C:\Program Files\PFConfig
2008-01-26 08:47 . 2008-01-26 08:47 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-26 08:47 . 2008-01-26 08:47 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-26 08:46 . 2008-01-26 08:47 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-01-26 08:46 . 2008-01-26 08:46 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-25 18:45 . 2008-01-25 19:10 <DIR> d-------- C:\Program Files\ABC Amber Photoshop Converter
2008-01-25 17:01 . 2008-01-25 17:02 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-01-25 14:20 . 2008-01-26 21:38 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Application Data\Ventrilo
2008-01-25 14:18 . 2008-01-25 14:18 <DIR> d-------- C:\Program Files\Ventrilo
2008-01-25 13:05 . 2008-01-25 13:05 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-24 21:50 . 2008-01-24 21:51 <DIR> d-------- C:\Program Files\Copy of Image-Line
2008-01-24 19:28 . 2008-01-24 21:32 <DIR> d-------- C:\Program Files\VstPlugins
2008-01-24 19:28 . 2008-01-24 19:28 <DIR> d-------- C:\Program Files\ASIO4ALL v2
2008-01-24 19:28 . 2002-07-08 09:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-01-24 19:28 . 2006-06-20 19:56 225,280 --a------ C:\WINDOWS\system32\rewire.dll
2008-01-24 19:27 . 2008-01-24 21:32 <DIR> d-------- C:\Program Files\Image-Line
2008-01-24 16:38 . 2008-01-24 16:38 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-24 15:51 . 2008-01-24 15:51 <DIR> d-------- C:\Program Files\uTorrent
2008-01-24 15:51 . 2008-01-29 10:52 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Application Data\uTorrent
2008-01-23 17:35 . 2007-10-26 11:20 4,124,352 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-01-23 17:34 . 2008-01-23 17:34 <DIR> d-------- C:\Program Files\Realtek AC97
2008-01-23 17:34 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-01-23 17:34 . 2006-07-31 11:19 315,392 --a------ C:\WINDOWS\alcupd.exe
2008-01-23 17:34 . 2006-07-31 11:27 217,088 --a------ C:\WINDOWS\alcrmv.exe
2008-01-23 17:34 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
2008-01-23 14:17 . 2008-01-23 14:17 <DIR> d-------- C:\Program Files\Common Files\EasyInfo
2008-01-23 14:04 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-01-23 13:42 . 2008-01-23 13:42 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Application Data\DivX
2008-01-23 12:51 . 2008-01-28 19:13 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Contacts
2008-01-23 09:50 . 2008-01-23 09:50 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Application Data\My Games
2008-01-23 09:13 . 2008-01-23 09:13 <DIR> d-------- C:\Program Files\Firaxis Games
2008-01-23 09:12 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-01-22 13:40 . 2008-01-29 16:13 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-22 13:40 . 2008-01-22 13:40 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-22 13:05 . 2008-01-22 13:05 <DIR> d-------- C:\Program Files\iTunes
2008-01-22 13:05 . 2008-01-22 13:05 <DIR> d-------- C:\Program Files\iPod
2008-01-22 13:05 . 2008-01-22 14:05 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Application Data\Apple Computer
2008-01-22 13:04 . 2008-01-23 12:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-22 13:04 . 2008-01-22 13:04 <DIR> d-------- C:\Program Files\QuickTime
2008-01-22 13:04 . 2008-01-22 13:04 <DIR> d-------- C:\Program Files\Bonjour
2008-01-22 13:04 . 2008-01-22 13:04 <DIR> d-------- C:\Program Files\Apple Software Update
2008-01-22 13:04 . 2008-01-22 13:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-22 13:03 . 2008-01-22 13:03 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-01-22 13:03 . 2008-01-22 13:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-22 09:44 . 2008-01-22 09:45 <DIR> d-------- C:\Program Files\DivX
2008-01-22 07:14 . 2008-01-23 12:47 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-01-22 07:09 . 2008-01-27 13:45 <DIR> d-------- C:\Program Files\World Of Warcraft
2008-01-21 22:10 . 2008-01-21 22:10 <DIR> d-------- C:\Program Files\EA Games
2008-01-21 21:51 . 2008-01-21 21:51 1,167 --a------ C:\WINDOWS\mozver.dat
2008-01-21 20:25 . 2008-01-21 20:25 <DIR> d-------- C:\Documents and Settings\MC Anthrax\Application Data\acccore
2008-01-21 20:05 . 2008-01-21 20:05 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-01-21 20:05 . 2008-01-21 20:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-01-21 20:05 . 2008-01-21 20:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-01-21 20:03 . 2008-01-29 16:08 <DIR> d-------- C:\Program Files\Viewpoint
2008-01-21 20:03 . 2008-01-21 20:03 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-01-21 20:03 . 2008-01-21 20:03 <DIR> d-------- C:\Program Files\AIM6
2008-01-21 20:03 . 2008-01-29 16:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-21 20:03 . 2008-01-21 20:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-21 20:03 . 2008-01-21 20:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-01-21 20:03 . 2008-01-21 20:03 492 --ah----- C:\IPH.PH
2008-01-21 19:37 . 2008-01-21 19:37 <DIR> d-------- C:\Program Files\Realtek
2008-01-21 18:30 . 2008-01-21 18:30 847 --a------ C:\WINDOWS\Active Setup Log.BAK
2008-01-21 18:12 . 2008-01-21 18:12 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-21 18:11 . 2008-01-23 12:50 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-21 18:10 . 2008-01-23 12:50 <DIR> d-------- C:\Program Files\Windows Live
2008-01-21 18:10 . 2008-01-23 12:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-21 18:06 . 2008-01-21 18:06 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-01-21 18:04 . 2005-02-25 14:35 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-21 18:00 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-01-21 18:00 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-01-21 18:00 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-01-21 18:00 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-01-21 18:00 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-01-21 17:57 . 2008-01-21 17:57 <DIR> d---s---- C:\Documents and Settings\MC Anthrax\UserData
2008-01-21 17:54 . 2008-01-29 16:14 <DIR> d-------- C:\Program Files\Steam
2008-01-21 17:54 . 2008-01-21 17:54 <DIR> d-------- C:\Program Files\ATI Technologies
2008-01-21 17:54 . 2007-12-20 21:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-01-21 17:50 . 2008-01-24 09:02 15,227 --a------ C:\scan.html
2008-01-21 17:02 . 2008-01-23 17:34 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-01-21 17:02 . 2008-01-21 17:02 <DIR> d-------- C:\Program Files\D-Link
2008-01-21 17:02 . 2008-01-21 17:02 <DIR> d-------- C:\Program Files\ANI
2008-01-21 17:01 . 2008-01-21 19:37 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-01-21 05:52 --------- d--h--w C:\Program Files\Uninstall Information
2008-01-21 05:48 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-21 03:53 2,843,136 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-12-21 03:09 368,640 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-21 03:08 272,384 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-21 03:02 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-12-21 02:59 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-21 02:59 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-21 02:59 147,456 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-21 02:59 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-21 02:58 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-21 02:57 512,000 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-21 02:56 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-21 02:53 9,826,304 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-21 02:47 3,120,640 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-21 02:36 1,661,696 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-21 02:24 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2007-12-21 02:20 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-21 02:20 385,024 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-21 02:18 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-21 02:17 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-12-21 02:15 159,744 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-21 02:11 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-11-29 22:30 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-29 22:30 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-11-29 22:30 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-11-28 21:55 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 23:00 15360]
"Steam"="c:\program files\steam\steam.exe" [2008-01-21 18:07 1266936]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-04 03:15 50528]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-07-22 10:42 1519616]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49 49152]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 16:58 16264192 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 18:04 2879488 C:\WINDOWS\SkyTel.exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-01-28 08:08 1481472]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-02-28 23:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-01-28 08:08]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-01-28 08:08]
S3 happyfacesz;happyfacesz;C:\Documents and Settings\MC Anthrax\My Documents\thingo2\happyfacesz.sys []
S3 hhhhdgfa;hhhhdgfa;C:\Documents and Settings\MC Anthrax\My Documents\Gogleveling\BOTS\noob farming one\hhhhdgfa.sys [2008-01-29 10:18]
S3 nakja;nakja;C:\Documents and Settings\MC Anthrax\My Documents\Gogleveling\BOTS\Copy of Bg bot 1\nakja.sys [2008-01-27 19:39]
*Newly Created Service* - PROCEXP90
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-29 16:17:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\guard32.dll
.
Completion time: 2008-01-29 16:17:17
ComboFix-quarantined-files.txt 2008-01-29 05:17:15