Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.257 [GMT 1:00]
Running from: C:\DOCUME~1\Ruth_07\LOCALS~1\Temp\Rar$EX04.094\ComboFix-www.PcHurricane.com-.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-28 22:22 . 2008-08-28 22:23 <DIR> d-------- C:\ComboFix
2008-08-28 21:54 . 2008-08-28 21:53 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-08-28 21:52 . 2008-08-28 21:55 <DIR> d-------- C:\Documents and Settings\Ruth_07\.housecall6.6
2008-08-28 06:18 . 2008-08-28 06:18 91 --a------ C:\WINDOWS\wininit.ini
2008-08-27 21:43 . 2008-08-27 21:43 <DIR> d-------- C:\Documents and Settings\Jams\Application Data\AVGTOOLBAR
2008-08-27 21:21 . 2008-08-30 13:43 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-27 21:16 . 2008-08-30 13:15 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-27 21:16 . 2008-08-27 21:16 <DIR> d-------- C:\Program Files\AVG
2008-08-27 21:16 . 2008-08-27 23:37 <DIR> d-------- C:\Documents and Settings\Ruth_07\Application Data\AVGTOOLBAR
2008-08-27 21:16 . 2008-08-27 21:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-27 21:16 . 2008-08-29 17:13 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 21:16 . 2008-08-27 21:16 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-27 21:16 . 2008-08-27 21:16 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-27 20:30 . 2008-08-27 20:30 347 --ahs---- C:\WINDOWS\system32\sBbacccf.ini2
2008-08-23 10:57 . 2008-08-28 18:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-08-23 10:53 . 2008-08-23 10:53 <DIR> d-------- C:\Program Files\Common Files\iS3
2008-08-23 10:53 . 2008-08-28 21:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-08-22 14:22 . 2008-08-22 14:23 1,370,363 --ahs---- C:\WINDOWS\system32\yiyltoov.ini
2008-08-22 14:18 . 2008-08-28 06:29 543,919 --ahs---- C:\WINDOWS\system32\wxGQYJjl.ini2
2008-08-22 14:18 . 2008-08-28 06:31 543,919 --ahs---- C:\WINDOWS\system32\wxGQYJjl.ini
2008-08-22 14:07 . 2008-08-22 11:42 98,304 --a------ C:\WINDOWS\enqx.exe
2008-08-22 14:07 . 2008-08-22 11:42 86,016 --a------ C:\WINDOWS\tqwolser.exe
2008-08-20 08:58 . 2008-08-20 08:58 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-08-20 08:56 . 2008-08-20 08:56 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-08-20 08:56 . 2008-08-20 08:56 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-13 00:02 . 2008-08-13 00:03 <DIR> d-------- C:\Documents and Settings\Ruth_07\Application Data\Vso
2008-08-13 00:02 . 2008-08-13 00:02 87,608 --a------ C:\Documents and Settings\Ruth_07\Application Data\ezpinst.exe
2008-08-13 00:02 . 2008-08-13 00:02 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-08-13 00:02 . 2008-08-13 00:02 47,360 --a------ C:\Documents and Settings\Ruth_07\Application Data\pcouffin.sys
2008-08-13 00:01 . 2008-08-13 00:02 <DIR> d-------- C:\Program Files\copy to dvd
2008-08-07 23:03 . 2008-08-07 23:15 <DIR> d-------- C:\Documents and Settings\Jams\Application Data\uTorrent
2008-07-30 22:06 . 2008-07-30 22:06 <DIR> d-------- C:\Documents and Settings\Jams\Phone Browser
2008-07-30 21:34 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-30 21:34 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-30 21:34 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-07-30 21:34 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-28 23:45 . 2008-07-28 23:45 <DIR> d-------- C:\Documents and Settings\Jams\Application Data\Nero
2008-07-28 18:56 . 2008-07-28 18:56 <DIR> d-------- C:\Program Files\AskTBar
2008-07-25 21:02 . 2008-07-25 21:02 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-25 21:02 . 2008-07-25 21:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-25 20:48 . 2008-07-26 08:10 1,536,368 --ahs---- C:\WINDOWS\system32\qohmqwxq.ini
2008-07-25 19:30 . 2008-07-25 19:38 <DIR> d-------- C:\Program Files\XoftSpySE
2008-07-25 19:08 . 2008-08-30 13:42 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-22 19:05 . 2008-07-22 19:08 1,887 --a------ C:\WINDOWS\diagwrn.xml
2008-07-22 19:05 . 2008-07-22 19:08 1,887 --a------ C:\WINDOWS\diagerr.xml
2008-07-20 16:15 . 2008-07-20 09:05 98,304 --a------ C:\WINDOWS\agpqlrfm.exe
2008-07-12 18:42 . 2008-07-12 18:42 <DIR> d-------- C:\Documents and Settings\Jams\Application Data\Apple Computer
2008-07-03 18:07 . 2008-07-03 18:07 <DIR> d-------- C:\Program Files\iPod
2008-07-03 18:06 . 2008-07-03 18:07 <DIR> d-------- C:\Program Files\iTunes
2008-07-03 18:05 . 2008-08-22 15:44 <DIR> d-------- C:\Program Files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-30 13:01 --------- d-----w C:\Documents and Settings\Ruth_07\Application Data\uTorrent
2008-08-28 19:15 --------- d-----w C:\Program Files\Common Files\Nero
2008-08-28 19:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-27 21:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-06 21:18 --------- d-----w C:\Program Files\Java
2008-07-20 15:36 --------- d-----w C:\Program Files\Common Files\Ahead
2008-07-20 15:36 --------- d-----w C:\Program Files\Ahead
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:12 667,136 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-01-20 13:43 259 ----a-w C:\Program Files\internet explorer\plugins\IEImageRR.dll
.
------- Sigcheck -------
1980-01-05 09:14 502272 6225f14b8ce08ccba8b25ad27843c674 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-08-25_21.12.46.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-22 23:41:29 26,952 -c--a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-08-27 20:16:15 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-08-27 19:31:57 2,732 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-20 13:41 185896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 17:13 1235736]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\ljJYQGxw
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Ruth_07^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Ruth_07\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Ruth_07^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Ruth_07\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"E:\\utorrent.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 17:13]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 17:13]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 17:13]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-27 21:16]
R3 s3m;s3m;C:\WINDOWS\system32\DRIVERS\s3m.sys [2001-08-17 13:50]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C800000-ECBD-15CF-3B95-00AA005B3383}]
C:\Program Files\Internet Explorer\PLUGINS\cxsrrs.exe
.
Contents of the 'Scheduled Tasks' folder
2008-05-27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe []
2008-08-30 C:\WINDOWS\Tasks\XoftSpySE 2.job
- C:\Program Files\XoftSpySE\XoftSpy.exe [2008-07-25 16:22]
2008-07-25 C:\WINDOWS\Tasks\XoftSpySE.job
- C:\Program Files\XoftSpySE\XoftSpy.exe [2008-07-25 16:22]
.
- - - - ORPHANS REMOVED - - - -
BHO-{0C5C4DB4-6C62-49ED-8343-62B9AE7ADF6A} - C:\WINDOWS\system32\awtrqrRJ.dll
BHO-{5B08EC46-2A36-43A5-A14B-9A20E152B89F} - C:\WINDOWS\system32\ljJYQGxw.dll
Toolbar-SITEguard - (no file)
HKLM-Run-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
ShellExecuteHooks-{0C5C4DB4-6C62-49ED-8343-62B9AE7ADF6A} - C:\WINDOWS\system32\awtrqrRJ.dll
Notify-awtrqrRJ - awtrqrRJ.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Ruth_07\Application Data\Mozilla\Firefox\Profiles\biqr3026.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.co.uk/
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-30 14:07:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-30 14:10:52
ComboFix-quarantined-files.txt 2008-08-30 13:10:41
ComboFix2.txt 2008-08-26 21:55:04
ComboFix3.txt 2008-08-26 21:39:19
ComboFix4.txt 2008-08-26 21:14:55
ComboFix5.txt 2008-08-30 13:05:02
Pre-Run: 6,491,766,784 bytes free
Post-Run: 6,487,199,744 bytes free
171 --- E O F --- 2008-08-20 15:45:10