ComboFix 09-09-28.01 - Holmes 29/09/2009 9:54.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.1023.640 [GMT 8:00]
Running from: c:\documents and settings\Holmes\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\1debca.msp
c:\windows\Installer\2282198.msp
c:\windows\Installer\22e6ef.msi
c:\windows\Installer\22e6f0.msp
c:\windows\Installer\22e6f1.msp
c:\windows\Installer\22e6f2.msp
c:\windows\Installer\22e6f3.msp
c:\windows\Installer\22e6f4.msp
c:\windows\Installer\22e6f5.msp
c:\windows\Installer\22e6f6.msp
c:\windows\Installer\22e6f7.msp
c:\windows\Installer\22e6f8.msp
c:\windows\Installer\22e6f9.msp
c:\windows\Installer\22e762.msi
c:\windows\Installer\22e763.msp
c:\windows\Installer\22e764.msp
c:\windows\Installer\22e765.msp
c:\windows\Installer\22e766.msp
c:\windows\Installer\22e767.msp
c:\windows\Installer\22e768.msp
c:\windows\Installer\22e769.msp
c:\windows\Installer\22e76a.msp
c:\windows\Installer\22e76b.msp
c:\windows\Installer\22e76c.msp
c:\windows\Installer\2305bc.msp
c:\windows\Installer\2ff165.msp
c:\windows\Installer\2ff1aa.msp
c:\windows\Installer\34cd9.msp
c:\windows\Installer\35fe4.msp
c:\windows\Installer\3c12c.msp
c:\windows\Installer\3c12d.msp
c:\windows\Installer\3c12e.msp
c:\windows\Installer\3c12f.msp
c:\windows\Installer\3c130.msp
c:\windows\Installer\3c131.msp
c:\windows\Installer\3c132.msp
c:\windows\Installer\3c133.msp
c:\windows\Installer\3c134.msp
c:\windows\Installer\3c135.msp
c:\windows\Installer\5b7719.msp
c:\windows\Installer\5de2b.msp
c:\windows\Installer\9d0306.msi
c:\windows\Installer\9e47d.msp
c:\windows\Installer\aefe11.msp
c:\windows\Installer\eb506.msp
----- BITS: Possible infected sites -----
hxxp://au.download.windowj+|Cv+@J:NGD_DQ{zcxLJS@(K8AMesse nger Update.S-1-5-21-1417001333-796845957-2147169803-1003XtD$?uuT~
.
((((((((((((((((((((((((( Files Created from 2009-08-28 to 2009-09-29 )))))))))))))))))))))))))))))))
.
2009-09-28 23:13 . 2009-09-28 23:14 -------- d-----w- c:\windows\LastGood
2009-09-28 23:13 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-09-23 15:13 . 2009-08-25 09:04 75264 ----a-w- c:\windows\system32\uc_holybeast_launching.dll
2009-09-23 15:11 . 2009-08-16 23:48 158952 ----a-w- c:\windows\system32\PubPlugin.dll
2009-09-23 15:10 . 2009-09-23 15:10 -------- d-----w- C:\Temp
2009-09-23 15:10 . 2009-07-02 16:34 83376 ----a-w- c:\temp\npijjiautoinstallpluginff.dll
2009-09-23 15:10 . 2009-07-02 16:34 710064 ----a-w- c:\windows\system32\ijjiSetup.exe
2009-09-23 15:10 . 2009-07-02 16:34 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-09-23 15:10 . 2009-07-02 16:34 58800 ----a-w- c:\windows\system32\ijjiPlugin2.dll
2009-09-23 15:10 . 2009-07-01 02:25 61440 ----a-w- c:\windows\system32\uc_atlantica_launching.dll
2009-09-23 15:10 . 2009-06-23 05:21 64000 ----a-w- c:\windows\system32\uc_sfighters_launching.dll
2009-09-23 15:10 . 2009-03-31 09:43 53248 ----a-w- c:\windows\system32\uc_luminary_launching.dll
2009-09-23 15:10 . 2009-03-11 10:20 208384 ----a-w- c:\windows\system32\uc_rohan_launching.dll
2009-09-23 15:10 . 2009-01-29 03:53 87472 ----a-w- c:\windows\system32\ijjiChannelingPlugin.dll
2009-09-23 15:10 . 2009-09-23 15:10 -------- d-----w- c:\program files\ijji
2009-09-23 14:46 . 2009-09-23 14:46 -------- d-----w- C:\ijji
2009-09-23 02:36 . 2009-09-23 02:36 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-09-21 08:14 . 2009-09-21 11:12 -------- d-----w- c:\documents and settings\Holmes\temp
2009-09-11 10:06 . 2009-09-11 10:06 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCach e
2009-09-10 23:58 . 2009-09-10 23:58 -------- d-----w- c:\documents and settings\Holmes\Local Settings\Application Data\WLDM
2009-09-10 09:50 . 2009-09-28 23:24 -------- d-----w- c:\documents and settings\Holmes\Tracing
2009-09-10 09:11 . 2009-09-10 09:11 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-09 00:23 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-05 12:07 . 2009-09-05 12:07 -------- d-----w- c:\windows\Performance
2009-09-05 12:06 . 2009-09-15 02:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Corporation
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-09-28 23:18 . 2009-07-15 14:56 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-28 23:13 . 2009-07-15 15:25 -------- d-----w- c:\program files\Microsoft
2009-09-28 10:20 . 2007-11-16 05:26 -------- d-----w- c:\program files\Trend Micro
2009-09-28 03:28 . 2008-07-16 13:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-28 02:10 . 2009-08-05 03:34 -------- d-----w- c:\program files\Steam
2009-09-28 01:38 . 2008-07-16 08:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-25 11:41 . 2007-10-17 08:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-23 15:10 . 2007-10-07 07:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-12 08:54 . 2007-10-09 05:09 -------- d-----w- c:\program files\Full Tilt Poker
2009-09-10 09:52 . 2008-01-19 01:08 -------- d-----w- c:\program files\Windows Live
2009-09-10 06:54 . 2008-07-20 07:44 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 06:53 . 2008-07-16 13:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 01:01 . 2009-08-12 02:59 -------- d-----w- c:\documents and settings\Holmes\Application Data\Ventrilo
2009-08-16 01:44 . 2008-12-24 01:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-16 01:44 . 2008-12-24 01:26 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-16 01:43 . 2008-12-24 01:26 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-15 04:08 . 2007-10-16 05:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-15 03:06 . 2009-08-15 03:06 -------- d-----w- c:\documents and settings\Holmes\Application Data\SpinTop Games
2009-08-15 03:05 . 2009-08-15 03:05 -------- d-----w- c:\documents and settings\Holmes\Application Data\SpinTop
2009-08-12 02:54 . 2009-08-12 02:53 -------- d-----w- c:\program files\Ventrilo
2009-08-12 02:50 . 2008-07-16 10:10 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-10 08:34 . 2009-08-10 08:34 -------- d-----w- c:\program files\Microsoft LifeChat
2009-08-05 09:01 . 2006-02-28 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 07:40 . 2008-01-11 04:14 -------- d-----w- c:\program files\NVIDIA Corporation
2009-08-05 07:40 . 2009-08-05 07:40 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-08-05 00:13 . 2007-10-09 09:15 -------- d-----w- c:\program files\Java
2009-08-03 23:52 . 2008-12-24 01:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg8
2009-08-03 07:07 . 2009-08-03 07:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 07:07 . 2009-08-03 07:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-08-03 07:07 . 2008-12-31 08:04 403816 ----a-w- c:\windows\system32\OGACheckControl.DLL
2009-07-26 08:44 . 2009-07-26 08:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-24 21:23 . 2008-12-02 21:46 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2006-02-28 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 18:54 . 2009-08-05 07:38 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-07-14 18:54 . 2009-08-05 07:38 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-07-14 18:54 . 2009-08-05 07:38 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-07-14 18:54 . 2008-05-16 06:01 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-07-14 18:54 . 2008-01-11 03:27 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-07-14 18:54 . 2007-06-28 16:43 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-07-14 18:54 . 2007-06-28 16:43 7741664 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-07-14 18:54 . 2007-06-28 16:43 5842816 ----a-w- c:\windows\system32\nv4_disp.dll
2009-07-14 18:54 . 2007-06-28 16:43 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-07-14 18:54 . 2007-06-28 16:43 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-07-14 18:54 . 2007-06-28 16:43 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-07-14 05:35 . 2009-07-14 05:35 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-07-14 05:35 . 2009-07-14 05:35 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-07-14 05:35 . 2009-07-14 05:35 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-07-14 05:35 . 2009-07-14 05:35 3170304 ----a-w- c:\windows\system32\nvwss.dll
2009-07-14 05:34 . 2009-07-14 05:34 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-07-14 05:34 . 2009-07-14 05:34 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-07-14 05:34 . 2009-07-14 05:34 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-07-14 05:34 . 2009-07-14 05:34 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-07-14 05:34 . 2009-07-14 05:34 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-07-14 05:34 . 2009-07-14 05:34 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-07-14 05:34 . 2009-07-14 05:34 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-07-14 05:34 . 2009-07-14 05:34 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-07-14 05:34 . 2009-07-14 05:34 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-07-13 15:43 . 2006-02-28 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 23:01 . 2008-02-16 12:11 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-07-09 10:49 . 2007-10-07 11:07 64952 ----a-w- c:\documents and settings\Holmes\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-03 17:09 . 2006-02-28 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2008-07-16 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-16 2007832]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-09-28 520024]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-04-22 68592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-07-08 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2009-07-14 86016]
"LifeChat"="c:\program files\Microsoft LifeChat\LifeChat.exe" [2008-08-21 267296]
"SmartDefrag"="c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2009-07-02 2453264]
"WindowsLivePhone"="c:\program files\Windows Live\Device Manager\msgrdvmn.exe" [2008-12-22 787816]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-02-25 437160]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 01:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Westwood\\RA2\\gamemd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17/02/2009 9:14 AM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [24/12/2008 9:26 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [24/12/2008 9:26 AM 108552]
R1 f4cd7848-3e92-4732-80a1-63c7ed58f8ac;f4cd7848-3e92-4732-80a1-63c7ed58f8ac;c:\windows\iprot\f4cd7848-3e92-4732-80a1-63c7ed58f8ac\PhysMem.sys [20/06/2009 11:41 AM 3584]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [24/12/2008 9:25 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [24/12/2008 9:25 AM 297752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 5:34 AM 1028432]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3/11/2006 6:19 PM 13592]
S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [30/03/2009 4:28 PM 1533808]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - WLIDSVC
*Deregistered* - dump_wmimmc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSe tup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:16]
2009-09-28 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2006-02-28 00:12]
2009-09-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-16 00:55]
2009-08-10 c:\windows\Tasks\LifeChatTask.job
- c:\program files\Microsoft LifeChat\LifeChat.exe [2008-08-21 03:16]
2009-09-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 10:20]
2009-09-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 07:07]
2009-09-03 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-23 01:22]
2009-09-25 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-02-07 06:31]
2009-09-28 c:\windows\Tasks\User_Feed_Synchronization-{429F466D-E604-4FF4-9DE3-1299FC3A1067}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bigpond.com/homepage/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {4C68DACE-E6BC-4650-9C7E-D036720CA729} - hxxp://avs.liveprotect.net/onscan/tyscan/nps.cab
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-09-29 10:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\n pggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1417001333-796845957-2147169803-1003\Software\SecuROM\License information*]
"datasecu"=hex:fc,57,f5,6f,33,a7,73,c6,b8,fc,53,fd ,a6,b2,8c,4c,b6,6f,d3,dc,5a,
c6,92,6f,f4,b9,6e,8d,93,02,81,fb,4d,19,05,0e,4c,87 ,a1,0d,f0,e2,3a,ce,9c,a2,\
"rkeysecu"=hex:31,49,d7,e2,10,45,57,43,89,4a,3c,f3 ,9d,df,44,c6
.
Completion time: 2009-09-29 10:02
ComboFix-quarantined-files.txt 2009-09-29 02:02
Pre-Run: 47,142,105,088 bytes free
Post-Run: 47,193,325,568 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect
278 --- E O F --- 2009-09-28 22:58
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:10:24 AM, on 29/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Microsoft LifeChat\LifeChat.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\Windows Live\Device Manager\msgrdvmn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
BigPond Broadband - Wireless, ADSL, Cable and dialup internet access
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\s wg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe"
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [WindowsLivePhone] C:\Program Files\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20Lost%20in%20Los%20Angeles/Images/stg_drm.ocx
O16 - DPF: {4C68DACE-E6BC-4650-9C7E-D036720CA729} -
http://avs.liveprotect.net/onscan/tyscan/nps.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20Lost%20in%20Los%20Angeles/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 8770 bytes