ComboFix 08-01-29.3 - Michael 2008-01-29 17:01:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.148 [GMT 0:00]
Running from: C:\Documents and Settings\Michael\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\jkkjk.dll
C:\WINDOWS\system32\rqrpnlk.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\cookies.ini
C:\WINDOWS\pp.exe
C:\WINDOWS\system32\jkkjk.dll
C:\WINDOWS\system32\kjkkj.ini
C:\WINDOWS\system32\kjkkj.ini2
C:\WINDOWS\system32\rqrpnlk.dll
C:\WINDOWS\system32\rtutv.bak2
C:\WINDOWS\system32\rtutv.ini
----- BITS: Possible infected sites -----
hxxp://gpdl.google.com
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-29 16:56 . 2008-01-29 16:56 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-27 17:21 . 2008-01-27 17:21 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\Lavasoft
2008-01-27 16:24 . 2008-01-27 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-27 15:36 . 2008-01-27 15:36 <DIR> d-------- C:\Program Files\orange3
2008-01-27 15:36 . 2008-01-27 15:36 <DIR> d-------- C:\Program Files\Orange
2008-01-27 12:01 . 2008-01-27 12:02 35 --a------ C:\WINDOWS\InfModM.ini
2008-01-21 21:48 . 2006-07-27 15:37 19,220 --------- C:\WINDOWS\wwdslcfg.ini
2008-01-06 19:39 . 2008-01-06 19:39 <DIR> d-------- C:\WINDOWS\system32\runtime
2008-01-06 19:39 . 2008-01-16 20:17 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 23:04 . 2007-12-30 23:04 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\Talkback
2007-12-30 22:45 . 2007-12-30 22:45 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-30 22:41 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-01-29 16:51 --------- d-----w C:\Documents and Settings\Michael\Application Data\AVG7
2008-01-27 17:10 --------- d-s---w C:\Program Files\Common Files\Teknum Systems
2008-01-16 20:31 --------- d-----w C:\Program Files\Google
2008-01-16 20:12 --------- d-----w C:\Program Files\LimeWire
2007-12-26 17:44 --------- d-----w C:\Program Files\TalkTalk
2007-12-25 22:10 --------- d-----w C:\Program Files\Incomplete
2007-09-18 21:38 6,480 --sha-w C:\WINDOWS\system32\efhkj.bak1
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"EM_EXEC"="C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE " [2001-08-24 08:40 35328]
"ACTIVBOARD"="C:\Apps\ActivBoard\MMKeybd.exe" [2001-05-03 17:41 159744]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-23 16:42 98304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 02:48 36975]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-07 13:22 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-07 13:23 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhfe]
C:\WINDOWS\system32\jkhfe.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyaaay]
xxyaaay.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BT Broadband Help.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BT Broadband Help.lnk
backup=C:\WINDOWS\pss\BT Broadband Help.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClickMe]
--a------ 2001-09-12 16:21 1216512 C:\apps\ClickMe\ClickMe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Documents and Settings\Michael\Desktop\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
C:\WINDOWS\system32\P2P Networking\P2P Networking.exe
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2000-10-03 14:18]
R3 CICHAUD;NEC ICH 3D Environmental Audio;C:\WINDOWS\system32\drivers\cichaud.sys [2001-09-20 10:30]
R3 CICHHALA;CICHHALA;C:\WINDOWS\system32\drivers\cich hal.sys [2001-09-20 10:35]
R3 PxHelper;PxHelper;C:\WINDOWS\System32\drivers\PxHe lper.sys [2001-04-10 18:01]
S3 iadusb;MT882;C:\WINDOWS\system32\DRIVERS\glauiad.s ys []
S3 nhksrv;Netropa NHK Server;C:\Apps\ActivBoard\nhksrv.exe [2000-09-13 15:18]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 21:41]
S3 V90drv;v90drv;C:\WINDOWS\system32\DRIVERS\v90drv.s ys [2001-09-30 17:05]
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-29 17:11:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
.
************************************************** ************************
.
Completion time: 2008-01-29 17:14:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 17:14:03
.
2007-12-30 23:33:29 --- E O F ---