codeman0013
Active Member
Here's the backstory. Friend brings me this pc which she says when logged in freezes. When no internet is connected to it it will run but as soon as the internet is connected it freezes attaching combofix and hijack this logs.
ComboFix 08-12-02.02 - Cody 2008-12-05 16:55:34.3 - NTFSx86
Running from: F:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-05 to 2008-12-05 )))))))))))))))))))))))))))))))
.
2100-04-01 17:22 . 2008-04-08 14:41 194 --a------ c:\windows\X83_DS.ini
2100-02-24 14:15 . 2001-04-02 16:30 821 --a------ c:\windows\Lexmark_ICM.ini
2100-02-16 16:09 . 2001-02-16 15:37 62 --a------ c:\windows\system32\LXASUSCI.INI
2008-12-04 23:03 . 2008-12-04 23:03 <DIR> d-------- c:\program files\Trend Micro
2008-12-04 18:42 . 2008-12-04 18:42 <DIR> d-------- c:\documents and settings\Cody\Application Data\Lavasoft
2008-12-04 17:22 . 2008-12-04 17:22 <DIR> d-------- c:\documents and settings\Cody\Application Data\AVGTOOLBAR
2008-12-04 17:16 . 2005-07-12 00:52 <DIR> d-------- c:\documents and settings\Cody\Application Data\Jasc Software Inc
2008-12-04 17:16 . 2005-07-12 01:04 <DIR> d-------- c:\documents and settings\Cody\Application Data\Creative
2008-12-04 17:16 . 2008-12-04 20:35 <DIR> d-------- c:\documents and settings\Cody
2008-12-04 17:00 . 2008-12-04 17:00 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-04 17:00 . 2008-12-04 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-03 21:56 . 2008-12-03 21:56 118 --a------ c:\windows\system32\MRT.INI
2008-12-03 19:29 . 2004-08-04 00:56 21,504 --a------ c:\windows\system32\hidserv.dll
2008-12-03 19:29 . 2004-08-04 00:56 21,504 --a------ c:\windows\system32\dllcache\hidserv.dll
2008-12-03 19:28 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-12-03 19:28 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\dllcache\usbccgp.sys
2008-12-03 19:28 . 2004-08-03 22:58 14,848 --a------ c:\windows\system32\drivers\kbdhid.sys
2008-12-03 19:28 . 2004-08-03 22:58 14,848 --a------ c:\windows\system32\dllcache\kbdhid.sys
2008-12-03 19:28 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-12-03 19:28 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\dllcache\mouhid.sys
2008-12-03 19:28 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-12-03 19:28 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\dllcache\hidusb.sys
2008-11-30 09:03 . 2008-12-03 20:10 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-10 21:58 . 2008-11-10 21:58 415 --a------ C:\swupdate.conf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 03:24 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-04 02:23 --------- d-----w c:\program files\Gmail Notifier GPL
2008-12-04 02:23 --------- d-----w c:\documents and settings\Jerry\Application Data\Yahoo!
2008-12-04 02:22 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-30 14:08 --------- d-----w c:\program files\DynGate
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-18 14:42 --------- d-----w c:\program files\Common Files\AOL
2008-10-18 14:39 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 16:57 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 17:41 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-09-30 22:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\dllcache\win32k.sys
2001-06-20 22:19 40,960 ----a-w c:\program files\ACMonitor_X83.exe
2007-12-04 16:14 56 --sh--r c:\windows\system32\8BB0ABB5E4.sys
2007-12-04 16:14 1,682 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-12-03_20.20.00.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-01-28 19:44:28 258,296 ----a-w c:\windows\system32\dllcache\drmclien.dll
+ 2004-08-10 10:00:00 246,272 ----a-w c:\windows\system32\dllcache\drmclien.dll
- 2005-01-28 19:44:28 96,768 ----a-w c:\windows\system32\dllcache\drmstor.dll
+ 2004-08-10 10:00:00 92,672 ----a-w c:\windows\system32\dllcache\drmstor.dll
- 2004-08-10 09:11:42 39,424 ----a-w c:\windows\system32\dllcache\ehentt.dll
+ 2005-08-05 20:01:56 40,960 ----a-w c:\windows\system32\dllcache\ehentt.dll
- 2004-08-10 09:11:44 43,520 ----a-w c:\windows\system32\dllcache\ehjpnime.dll
+ 2005-08-05 20:01:56 45,056 ----a-w c:\windows\system32\dllcache\ehjpnime.dll
- 2004-08-10 09:11:44 151,552 ----a-w c:\windows\system32\dllcache\ehsqdb20.dll
+ 2005-08-05 20:01:58 151,552 ----a-w c:\windows\system32\dllcache\ehsqdb20.dll
- 2004-08-10 09:11:44 462,848 ----a-w c:\windows\system32\dllcache\ehsqqp20.dll
+ 2005-08-05 20:01:58 462,848 ----a-w c:\windows\system32\dllcache\ehsqqp20.dll
- 2004-08-10 09:11:44 110,592 ----a-w c:\windows\system32\dllcache\ehsqse20.dll
+ 2005-08-05 20:01:58 110,592 ----a-w c:\windows\system32\dllcache\ehsqse20.dll
+ 2004-09-29 23:04:48 61,440 ----a-w c:\windows\system32\dllcache\gacutil.exe
- 2004-08-10 10:00:00 407,552 ----a-w c:\windows\system32\dllcache\mstsc.exe
+ 2006-11-07 08:06:47 600,576 ----a-w c:\windows\system32\dllcache\mstsc.exe
- 2004-08-10 10:00:00 655,360 ----a-w c:\windows\system32\dllcache\mstscax.dll
+ 2006-11-13 06:02:58 1,866,240 ----a-w c:\windows\system32\dllcache\mstscax.dll
- 2006-05-14 08:44:08 181,248 ----a-w c:\windows\system32\dllcache\rasmans.dll
+ 2004-08-10 10:00:00 174,080 ----a-w c:\windows\system32\dllcache\rasmans.dll
- 2005-01-28 19:44:28 258,296 ----a-w c:\windows\system32\drmclien.dll
+ 2004-08-10 10:00:00 246,272 ----a-w c:\windows\system32\drmclien.dll
- 2005-01-28 19:44:28 96,768 ----a-w c:\windows\system32\drmstor.dll
+ 2004-08-10 10:00:00 92,672 ----a-w c:\windows\system32\drmstor.dll
- 2008-05-29 23:35:11 17,486,968 ----a-w c:\windows\system32\MRT.exe
+ 2008-11-03 22:10:26 17,318,336 ----a-w c:\windows\system32\MRT.exe
- 2006-05-14 08:44:08 181,248 ----a-w c:\windows\system32\rasmans.dll
+ 2004-08-10 10:00:00 174,080 ----a-w c:\windows\system32\rasmans.dll
+ 2004-08-10 10:00:00 36,096 ----a-w c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\intelppm.sys
+ 2004-08-10 10:00:00 36,096 ----a-w c:\windows\system32\ReinstallBackups\0019\DriverFiles\i386\intelppm.sys
+ 2008-04-14 00:12:36 7,680 ----a-w c:\windows\system32\spdwnwxp.exe
- 2006-10-16 22:10:58 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2007-08-11 01:46:18 26,488 ----a-w c:\windows\system32\spupdsvc.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 339,968 2004-08-25 17:52:00 c:\program files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 50,736 2006-09-26 00:52:48 c:\program files\Common Files\AOL\1135138273\ee\bak\AOLSoftware.exe
----a-w 41,824 2008-06-24 18:34:50 c:\program files\Common Files\AOL\1135138273\ee\aolsoftware.exe
----a-w 221,184 2004-07-27 21:50:42 c:\program files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe
----a-w 185,784 2006-10-05 01:48:39 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 992,808 2006-03-07 21:05:20 c:\program files\Copy of McAfee.com\personal firewall\bak\MPFTray.exe
----a-w 1,327,104 2004-08-22 21:31:28 c:\program files\Copy of McAfee.com\personal firewall\MpfTray.exe
----a-w 57,344 2003-09-17 15:43:36 c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\bak\CTSysVol.exe
----a-w 221,184 2003-09-04 01:12:44 c:\program files\Intel\Modem Event Monitor\bak\IntelMEM.exe
----a-w 267,048 2008-01-15 09:22:56 c:\program files\iTunes\bak\iTunesHelper.exe
----a-w 289,064 2008-07-30 15:47:56 c:\program files\iTunes\iTunesHelper.exe
----a-w 53,248 2001-06-14 18:42:26 c:\program files\LexmarkX83\bak\AcBtnMgr_X83.exe
----a-w 53,248 2001-06-14 18:42:26 c:\program files\LexmarkX83\AcBtnMgr_X83.exe
----a-w 40,960 2001-10-18 16:25:18 c:\program files\LexmarkX83\bak\ACMonitor_X83.exe
----a-w 40,960 2001-10-18 16:25:18 c:\program files\LexmarkX83\ACMonitor_X83.exe
----a-w 992,808 2006-03-07 21:05:20 c:\program files\McAfee.com\personal firewall\bak\MPFTray.exe
----a-w 1,327,104 2004-08-22 21:31:28 c:\program files\McAfee.com\personal firewall\MpfTray.exe
----a-w 1,694,208 2004-10-13 16:24:37 c:\program files\Messenger\bak\msmsgs.exe
----a-w 1,498,032 2003-04-15 02:05:20 c:\program files\Messenger\msmsgs.exe
----a-w 385,024 2008-01-10 21:27:36 c:\program files\QuickTime\bak\qttask.exe
----a-w 413,696 2008-05-27 15:50:30 c:\program files\QuickTime\QTTask.exe
----a-w 15,360 2004-08-10 10:00:00 c:\windows\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-10 10:00:00 c:\windows\system32\ctfmon.exe
----a-w 122,941 2005-05-31 10:33:00 c:\windows\system32\dla\bak\tfswctrl.exe
----a-w 36,864 2002-06-27 09:47:08 c:\windows\system32\spool\drivers\w32x86\3\bak\printray.exe
----a-w 36,864 2001-10-25 18:20:09 c:\windows\system32\spool\drivers\w32x86\3\printray.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 06:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLSPScheduler]
c:\program files\Common Files\AOL\1135138273\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-02-23 15:19 53248 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-08-05 13:56 64512 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2008-06-24 12:34 41824 c:\program files\Common Files\AOL\1135138273\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-07-27 15:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 09:47 289064 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Manager]
--a------ 2001-06-14 12:42 53248 c:\progra~1\LEXMAR~1\AcBtnMgr_X83.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Monitor]
--a------ 2001-10-18 10:25 40960 c:\progra~1\LEXMAR~1\ACMonitor_X83.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
--a------ 2004-08-22 15:31 1327104 c:\program files\McAfee.com\personal firewall\MpfTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
--a------ 2004-06-16 23:33 98304 c:\progra~1\McAfee\SPAMKI~1\MSKAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2004-10-25 12:18 1111552 c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2003-04-14 20:05 1498032 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
--a------ 2001-10-25 12:20 36864 c:\windows\system32\spool\drivers\w32x86\3\printray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun]
c:\program files\Common Files\AOL\1135138273\ee\SSCRun.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
c:\program files\Common Files\Real\Update_OB\realsched.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 00:00 90112 c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
c:\program files\Yahoo!\browser\ybrwicon.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a------ 2005-05-03 11:38 64512 c:\windows\system32\P17.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\DynGate\\DynGate.exe"=
"c:\\Program Files\\TeamViewer\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135138273\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135138273\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
2008-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-07-09 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\rundll32.exe [2004-08-10 04:00]
2008-11-08 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (ANN-Jerry).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php
IE: {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php -
TCP: {7FF66A99-8360-41D2-BC62-38A22EF0BA0E} = 192.168.1.1
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 16:57:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\77DBA2B83282EF28]
"ImagePath"="\??\c:\program files\Common Files\AOL\1135138273\ee\77DBA2B83282EF28\77DBA2B83282EF28"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\77DBA2B83282EF28]
"ImagePath"="\??\c:\program files\Common Files\AOL\1135138273\ee\77DBA2B83282EF28\77DBA2B83282EF28"
.
Completion time: 2008-12-05 16:59:01
ComboFix-quarantined-files.txt 2008-12-05 22:58:58
ComboFix2.txt 2008-12-04 03:31:29
ComboFix3.txt 2008-12-04 02:21:05
Pre-Run: 27,611,238,400 bytes free
Post-Run: 27,606,216,704 bytes free
270 --- E O F --- 2008-12-04 03:56:11
Hijack this log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:52:48 PM, on 12/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer3\TeamViewer_Host.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{7FF66A99-8360-41D2-BC62-38A22EF0BA0E}: NameServer = 192.168.1.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 6320 bytes
ComboFix 08-12-02.02 - Cody 2008-12-05 16:55:34.3 - NTFSx86
Running from: F:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-05 to 2008-12-05 )))))))))))))))))))))))))))))))
.
2100-04-01 17:22 . 2008-04-08 14:41 194 --a------ c:\windows\X83_DS.ini
2100-02-24 14:15 . 2001-04-02 16:30 821 --a------ c:\windows\Lexmark_ICM.ini
2100-02-16 16:09 . 2001-02-16 15:37 62 --a------ c:\windows\system32\LXASUSCI.INI
2008-12-04 23:03 . 2008-12-04 23:03 <DIR> d-------- c:\program files\Trend Micro
2008-12-04 18:42 . 2008-12-04 18:42 <DIR> d-------- c:\documents and settings\Cody\Application Data\Lavasoft
2008-12-04 17:22 . 2008-12-04 17:22 <DIR> d-------- c:\documents and settings\Cody\Application Data\AVGTOOLBAR
2008-12-04 17:16 . 2005-07-12 00:52 <DIR> d-------- c:\documents and settings\Cody\Application Data\Jasc Software Inc
2008-12-04 17:16 . 2005-07-12 01:04 <DIR> d-------- c:\documents and settings\Cody\Application Data\Creative
2008-12-04 17:16 . 2008-12-04 20:35 <DIR> d-------- c:\documents and settings\Cody
2008-12-04 17:00 . 2008-12-04 17:00 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-04 17:00 . 2008-12-04 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-03 21:56 . 2008-12-03 21:56 118 --a------ c:\windows\system32\MRT.INI
2008-12-03 19:29 . 2004-08-04 00:56 21,504 --a------ c:\windows\system32\hidserv.dll
2008-12-03 19:29 . 2004-08-04 00:56 21,504 --a------ c:\windows\system32\dllcache\hidserv.dll
2008-12-03 19:28 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-12-03 19:28 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\dllcache\usbccgp.sys
2008-12-03 19:28 . 2004-08-03 22:58 14,848 --a------ c:\windows\system32\drivers\kbdhid.sys
2008-12-03 19:28 . 2004-08-03 22:58 14,848 --a------ c:\windows\system32\dllcache\kbdhid.sys
2008-12-03 19:28 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-12-03 19:28 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\dllcache\mouhid.sys
2008-12-03 19:28 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-12-03 19:28 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\dllcache\hidusb.sys
2008-11-30 09:03 . 2008-12-03 20:10 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-10 21:58 . 2008-11-10 21:58 415 --a------ C:\swupdate.conf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 03:24 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-04 02:23 --------- d-----w c:\program files\Gmail Notifier GPL
2008-12-04 02:23 --------- d-----w c:\documents and settings\Jerry\Application Data\Yahoo!
2008-12-04 02:22 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-30 14:08 --------- d-----w c:\program files\DynGate
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-18 14:42 --------- d-----w c:\program files\Common Files\AOL
2008-10-18 14:39 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 16:57 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 17:41 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-09-30 22:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\dllcache\win32k.sys
2001-06-20 22:19 40,960 ----a-w c:\program files\ACMonitor_X83.exe
2007-12-04 16:14 56 --sh--r c:\windows\system32\8BB0ABB5E4.sys
2007-12-04 16:14 1,682 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-12-03_20.20.00.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-01-28 19:44:28 258,296 ----a-w c:\windows\system32\dllcache\drmclien.dll
+ 2004-08-10 10:00:00 246,272 ----a-w c:\windows\system32\dllcache\drmclien.dll
- 2005-01-28 19:44:28 96,768 ----a-w c:\windows\system32\dllcache\drmstor.dll
+ 2004-08-10 10:00:00 92,672 ----a-w c:\windows\system32\dllcache\drmstor.dll
- 2004-08-10 09:11:42 39,424 ----a-w c:\windows\system32\dllcache\ehentt.dll
+ 2005-08-05 20:01:56 40,960 ----a-w c:\windows\system32\dllcache\ehentt.dll
- 2004-08-10 09:11:44 43,520 ----a-w c:\windows\system32\dllcache\ehjpnime.dll
+ 2005-08-05 20:01:56 45,056 ----a-w c:\windows\system32\dllcache\ehjpnime.dll
- 2004-08-10 09:11:44 151,552 ----a-w c:\windows\system32\dllcache\ehsqdb20.dll
+ 2005-08-05 20:01:58 151,552 ----a-w c:\windows\system32\dllcache\ehsqdb20.dll
- 2004-08-10 09:11:44 462,848 ----a-w c:\windows\system32\dllcache\ehsqqp20.dll
+ 2005-08-05 20:01:58 462,848 ----a-w c:\windows\system32\dllcache\ehsqqp20.dll
- 2004-08-10 09:11:44 110,592 ----a-w c:\windows\system32\dllcache\ehsqse20.dll
+ 2005-08-05 20:01:58 110,592 ----a-w c:\windows\system32\dllcache\ehsqse20.dll
+ 2004-09-29 23:04:48 61,440 ----a-w c:\windows\system32\dllcache\gacutil.exe
- 2004-08-10 10:00:00 407,552 ----a-w c:\windows\system32\dllcache\mstsc.exe
+ 2006-11-07 08:06:47 600,576 ----a-w c:\windows\system32\dllcache\mstsc.exe
- 2004-08-10 10:00:00 655,360 ----a-w c:\windows\system32\dllcache\mstscax.dll
+ 2006-11-13 06:02:58 1,866,240 ----a-w c:\windows\system32\dllcache\mstscax.dll
- 2006-05-14 08:44:08 181,248 ----a-w c:\windows\system32\dllcache\rasmans.dll
+ 2004-08-10 10:00:00 174,080 ----a-w c:\windows\system32\dllcache\rasmans.dll
- 2005-01-28 19:44:28 258,296 ----a-w c:\windows\system32\drmclien.dll
+ 2004-08-10 10:00:00 246,272 ----a-w c:\windows\system32\drmclien.dll
- 2005-01-28 19:44:28 96,768 ----a-w c:\windows\system32\drmstor.dll
+ 2004-08-10 10:00:00 92,672 ----a-w c:\windows\system32\drmstor.dll
- 2008-05-29 23:35:11 17,486,968 ----a-w c:\windows\system32\MRT.exe
+ 2008-11-03 22:10:26 17,318,336 ----a-w c:\windows\system32\MRT.exe
- 2006-05-14 08:44:08 181,248 ----a-w c:\windows\system32\rasmans.dll
+ 2004-08-10 10:00:00 174,080 ----a-w c:\windows\system32\rasmans.dll
+ 2004-08-10 10:00:00 36,096 ----a-w c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\intelppm.sys
+ 2004-08-10 10:00:00 36,096 ----a-w c:\windows\system32\ReinstallBackups\0019\DriverFiles\i386\intelppm.sys
+ 2008-04-14 00:12:36 7,680 ----a-w c:\windows\system32\spdwnwxp.exe
- 2006-10-16 22:10:58 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2007-08-11 01:46:18 26,488 ----a-w c:\windows\system32\spupdsvc.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 339,968 2004-08-25 17:52:00 c:\program files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 50,736 2006-09-26 00:52:48 c:\program files\Common Files\AOL\1135138273\ee\bak\AOLSoftware.exe
----a-w 41,824 2008-06-24 18:34:50 c:\program files\Common Files\AOL\1135138273\ee\aolsoftware.exe
----a-w 221,184 2004-07-27 21:50:42 c:\program files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe
----a-w 185,784 2006-10-05 01:48:39 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 992,808 2006-03-07 21:05:20 c:\program files\Copy of McAfee.com\personal firewall\bak\MPFTray.exe
----a-w 1,327,104 2004-08-22 21:31:28 c:\program files\Copy of McAfee.com\personal firewall\MpfTray.exe
----a-w 57,344 2003-09-17 15:43:36 c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\bak\CTSysVol.exe
----a-w 221,184 2003-09-04 01:12:44 c:\program files\Intel\Modem Event Monitor\bak\IntelMEM.exe
----a-w 267,048 2008-01-15 09:22:56 c:\program files\iTunes\bak\iTunesHelper.exe
----a-w 289,064 2008-07-30 15:47:56 c:\program files\iTunes\iTunesHelper.exe
----a-w 53,248 2001-06-14 18:42:26 c:\program files\LexmarkX83\bak\AcBtnMgr_X83.exe
----a-w 53,248 2001-06-14 18:42:26 c:\program files\LexmarkX83\AcBtnMgr_X83.exe
----a-w 40,960 2001-10-18 16:25:18 c:\program files\LexmarkX83\bak\ACMonitor_X83.exe
----a-w 40,960 2001-10-18 16:25:18 c:\program files\LexmarkX83\ACMonitor_X83.exe
----a-w 992,808 2006-03-07 21:05:20 c:\program files\McAfee.com\personal firewall\bak\MPFTray.exe
----a-w 1,327,104 2004-08-22 21:31:28 c:\program files\McAfee.com\personal firewall\MpfTray.exe
----a-w 1,694,208 2004-10-13 16:24:37 c:\program files\Messenger\bak\msmsgs.exe
----a-w 1,498,032 2003-04-15 02:05:20 c:\program files\Messenger\msmsgs.exe
----a-w 385,024 2008-01-10 21:27:36 c:\program files\QuickTime\bak\qttask.exe
----a-w 413,696 2008-05-27 15:50:30 c:\program files\QuickTime\QTTask.exe
----a-w 15,360 2004-08-10 10:00:00 c:\windows\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-10 10:00:00 c:\windows\system32\ctfmon.exe
----a-w 122,941 2005-05-31 10:33:00 c:\windows\system32\dla\bak\tfswctrl.exe
----a-w 36,864 2002-06-27 09:47:08 c:\windows\system32\spool\drivers\w32x86\3\bak\printray.exe
----a-w 36,864 2001-10-25 18:20:09 c:\windows\system32\spool\drivers\w32x86\3\printray.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 06:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLSPScheduler]
c:\program files\Common Files\AOL\1135138273\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-02-23 15:19 53248 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-08-05 13:56 64512 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2008-06-24 12:34 41824 c:\program files\Common Files\AOL\1135138273\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-07-27 15:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 09:47 289064 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Manager]
--a------ 2001-06-14 12:42 53248 c:\progra~1\LEXMAR~1\AcBtnMgr_X83.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Monitor]
--a------ 2001-10-18 10:25 40960 c:\progra~1\LEXMAR~1\ACMonitor_X83.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
--a------ 2004-08-22 15:31 1327104 c:\program files\McAfee.com\personal firewall\MpfTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
--a------ 2004-06-16 23:33 98304 c:\progra~1\McAfee\SPAMKI~1\MSKAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2004-10-25 12:18 1111552 c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2003-04-14 20:05 1498032 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
--a------ 2001-10-25 12:20 36864 c:\windows\system32\spool\drivers\w32x86\3\printray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun]
c:\program files\Common Files\AOL\1135138273\ee\SSCRun.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
c:\program files\Common Files\Real\Update_OB\realsched.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 00:00 90112 c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
c:\program files\Yahoo!\browser\ybrwicon.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a------ 2005-05-03 11:38 64512 c:\windows\system32\P17.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\DynGate\\DynGate.exe"=
"c:\\Program Files\\TeamViewer\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135138273\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135138273\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
2008-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-07-09 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\rundll32.exe [2004-08-10 04:00]
2008-11-08 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (ANN-Jerry).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php
IE: {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php -
TCP: {7FF66A99-8360-41D2-BC62-38A22EF0BA0E} = 192.168.1.1
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 16:57:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\77DBA2B83282EF28]
"ImagePath"="\??\c:\program files\Common Files\AOL\1135138273\ee\77DBA2B83282EF28\77DBA2B83282EF28"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\77DBA2B83282EF28]
"ImagePath"="\??\c:\program files\Common Files\AOL\1135138273\ee\77DBA2B83282EF28\77DBA2B83282EF28"
.
Completion time: 2008-12-05 16:59:01
ComboFix-quarantined-files.txt 2008-12-05 22:58:58
ComboFix2.txt 2008-12-04 03:31:29
ComboFix3.txt 2008-12-04 02:21:05
Pre-Run: 27,611,238,400 bytes free
Post-Run: 27,606,216,704 bytes free
270 --- E O F --- 2008-12-04 03:56:11
Hijack this log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:52:48 PM, on 12/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer3\TeamViewer_Host.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{7FF66A99-8360-41D2-BC62-38A22EF0BA0E}: NameServer = 192.168.1.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 6320 bytes