ComboFix 08-08-26.02 - Owner 2008-08-27 3:34:57.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.443 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\4KYLD8J9\bin.clearspring.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\4KYLD8J9\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[2].txt
C:\WINDOWS\system32\gjjlm.ini2
C:\WINDOWS\system32\lnnmp.ini2
C:\WINDOWS\system32\lnnmp.tmp
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\opqss.ini2
C:\WINDOWS\system32\opqss.tmp
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-07-27 to 2008-08-27 )))))))))))))))))))))))))))))))
.
2008-08-26 04:16 . 2008-06-10 02:32 73,728 --a--c--- C:\WINDOWS\system32\javacpl.cpl
2008-08-26 04:08 . 2008-08-26 04:16 <DIR> d----c--- C:\Program Files\Java
2008-08-25 22:34 . 2008-08-25 22:34 <DIR> d----c--- C:\Program Files\Lavasoft
2008-08-25 22:32 . 2008-08-25 22:32 <DIR> d----c--- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-25 19:31 . 2008-08-25 19:31 <DIR> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-25 19:31 . 2008-08-25 19:31 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-08-25 19:31 . 2008-08-25 19:31 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-25 19:31 . 2008-08-17 15:05 38,472 --a--c--- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-25 19:31 . 2008-08-17 15:05 17,144 --a--c--- C:\WINDOWS\system32\drivers\mbam.sys
2008-08-25 08:35 . 2008-08-25 09:06 <DIR> d----c--- C:\Program Files\Yahoo!
2008-08-25 08:35 . 2008-08-25 08:37 <DIR> d----c--- C:\Program Files\CCleaner
2008-08-24 19:47 . 2008-08-27 03:29 <DIR> d--h-c--- C:\$AVG8.VAULT$
2008-08-24 18:49 . 2008-08-27 03:57 <DIR> d----c--- C:\WINDOWS\system32\drivers\Avg
2008-08-24 18:49 . 2008-08-24 18:49 96,520 --a--c--- C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-24 18:49 . 2008-08-24 18:49 10,520 --a--c--- C:\WINDOWS\system32\avgrsstx.dll
2008-08-24 18:48 . 2008-08-24 18:48 <DIR> d----c--- C:\Program Files\AVG
2008-08-24 18:48 . 2008-08-24 18:48 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-24 12:02 . 2008-08-24 18:28 <DIR> d----c--- C:\Program Files\Spybot - Search & Destroy
2008-08-24 09:24 . 2008-08-22 17:22 3,262 --a--c--- C:\WINDOWS\system32\2.ico
2008-08-24 09:23 . 2008-08-25 08:10 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\TmpRecentIcons
2008-08-24 09:20 . 2008-08-25 23:56 <DIR> d----c--- C:\Program Files\MSA
2008-08-24 09:20 . 2008-08-22 17:22 3,262 --a--c--- C:\WINDOWS\system32\1.ico
2008-08-24 07:52 . 2008-08-25 06:25 <DIR> d----c--- C:\Program Files\DNA
2008-08-20 11:34 . 2008-08-20 11:34 <DIR> d----c--- C:\Program Files\FileZilla Client
2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d----c--- C:\WINDOWS\system32\scripting
2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d----c--- C:\WINDOWS\system32\en
2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d----c--- C:\WINDOWS\l2schemas
2008-08-19 20:31 . 2008-04-13 19:12 712,704 -----c--- C:\WINDOWS\system32\windowscodecs.dll
2008-08-19 20:31 . 2008-04-13 19:12 346,112 -----c--- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-19 20:31 . 2008-04-13 19:12 276,992 -----c--- C:\WINDOWS\system32\wmphoto.dll
2008-08-19 20:31 . 2008-04-13 19:12 69,120 -----c--- C:\WINDOWS\system32\wlanapi.dll
2008-08-19 20:31 . 2008-04-13 19:12 53,248 -----c--- C:\WINDOWS\system32\tsgqec.dll
2008-08-19 20:31 . 2008-04-13 19:12 50,688 -----c--- C:\WINDOWS\system32\tspkg.dll
2008-08-19 20:30 . 2008-04-13 19:12 412,160 -----c--- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-19 20:30 . 2008-04-13 19:12 291,328 -----c--- C:\WINDOWS\system32\qagentrt.dll
2008-08-19 20:30 . 2008-04-13 19:12 290,304 -----c--- C:\WINDOWS\system32\rhttpaa.dll
2008-08-19 20:30 . 2008-04-13 19:12 150,528 -----c--- C:\WINDOWS\system32\qagent.dll
2008-08-19 20:30 . 2008-04-13 19:12 144,384 -----c--- C:\WINDOWS\system32\onex.dll
2008-08-19 20:30 . 2008-04-13 19:12 76,800 -----c--- C:\WINDOWS\system32\qutil.dll
2008-08-19 20:30 . 2008-04-13 19:12 62,464 -----c--- C:\WINDOWS\system32\qcliprov.dll
2008-08-19 20:30 . 2008-04-13 19:12 61,952 -----c--- C:\WINDOWS\system32\rasqec.dll
2008-08-19 20:30 . 2008-04-13 19:12 32,768 -----c--- C:\WINDOWS\system32\setupn.exe
2008-08-19 20:30 . 2008-04-13 13:40 10,240 -----c--- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-08-19 20:28 . 2008-04-13 19:11 650,752 -----c--- C:\WINDOWS\system32\dot3ui.dll
2008-08-19 20:27 . 2008-04-13 19:11 233,472 -----c--- C:\WINDOWS\system32\azroles.dll
2008-08-19 20:27 . 2008-04-13 19:11 136,192 -----c--- C:\WINDOWS\system32\aaclient.dll
2008-08-19 20:27 . 2008-04-13 19:11 12,800 -----c--- C:\WINDOWS\system32\credssp.dll
2008-08-19 20:27 . 2008-04-13 19:11 7,168 -----c--- C:\WINDOWS\system32\bitsprx4.dll
2008-08-14 14:40 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-08 08:52 . 2008-08-08 08:52 124,168 --a--c--- C:\WINDOWS\system32\PPPFilt.dll
2008-07-27 08:50 . 2008-07-27 08:50 20 --ahsc--- C:\ArcDeviceInfo
2008-07-27 08:48 . 2008-07-27 08:48 94 --a--c--- C:\WINDOWS\MusicRip.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-27 08:57 81,984 -c--a-w C:\WINDOWS\system32\bdod.bin
2008-08-26 10:46 --------- dc----w C:\Documents and Settings\Owner\Application Data\FileZilla
2008-08-26 10:10 --------- dc----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-08-26 03:36 --------- dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-25 13:59 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-25 12:42 --------- dc----w C:\Program Files\Eusing Free Registry Cleaner
2008-08-07 00:05 --------- dc----w C:\Program Files\MozyHome
2008-08-04 15:35 --------- dc----w C:\Program Files\Common Files\Adobe
2008-07-30 12:31 --------- dc----w C:\Program Files\Avery Wizard 3.1
2008-07-27 13:47 --------- dc----w C:\Documents and Settings\Owner\Application Data\ArcSoft
2008-07-27 11:19 --------- dc----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-07-18 01:18 --------- dc----w C:\Documents and Settings\Owner\Application Data\PACE Anti-Piracy
2008-07-18 01:18 --------- dc----w C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
2008-07-18 01:17 --------- dc----w C:\Program Files\Common Files\PACE Anti-Piracy
2008-07-18 01:00 --------- dc----w C:\Program Files\Write Brothers, Inc
2008-07-14 23:47 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-07-14 23:44 --------- dc----w C:\Program Files\Common Files\Avery
2008-07-14 15:25 53,752 -c--a-w C:\WINDOWS\system32\drivers\mozy.sys
2008-07-09 10:27 124,168 -c--a-w C:\WINDOWS\system32\WPPFilt.dll
2008-07-07 20:26 253,952 -c--a-w C:\WINDOWS\system32\es.dll
2008-07-02 19:31 86,792 -c--a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-06-24 16:43 74,240 -c--a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 -c--a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 -c--a-w C:\WINDOWS\system32\mswsock.dll
2007-07-04 12:14 25,715 -c--a-w C:\Program Files\ICOFormat-1.6f9-win.zip
2005-05-26 19:35 1,422 -c--a-w C:\Program Files\ReadMe.txt
2004-04-14 12:47 2,095,388 -c--a-w C:\Program Files\TaxCut_2003_California_InstallerC.exe
2004-04-14 12:20 17,462,272 -c--a-w C:\Program Files\TaxCut2003FederalEZB.exe
2004-04-13 10:46 219,840 -c--a-w C:\Program Files\MSNToolbarSetup_en-us_PPD.exe
2004-04-13 09:44 403,968 -c--a-w C:\Program Files\JustZIPit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4A9D-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4A9D-BDFE-192AAD5099B1}]
2008-07-14 10:26 2405680 --a--c--- C:\Program Files\MozyHome\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}]
2008-07-14 10:26 2405680 --a--c--- C:\Program Files\MozyHome\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"RCUI"="C:\PROGRA~1\RINGCE~1\RINGCE~1\RCUI.exe" [2007-11-29 19:48 380928]
"RCHotKey"="C:\PROGRA~1\RINGCE~1\RINGCE~1\RCHotKey.exe" [2007-11-29 19:44 18944]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 14:32 94208]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 18:41 1832272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 10:01 110592]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 23:42 212992]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 07:03 221184]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 16:55 155648]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 04:55 483328]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-03-09 15:30 188416]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 14:54 241664]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 16:51 118784]
"CamMonitor"="c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 09:23 90112]
"FileZilla Server Interface"="C:\Program Files\FileZilla Server\FileZilla Server Interface.exe" [2007-10-19 13:05 937984]
"RCHotKey"="C:\PROGRA~1\RINGCE~1\RINGCE~1\RCHotKey.exe" [2007-11-29 19:44 18944]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-07-02 14:31 368640]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-24 18:49 1232152]
"LTMSG"="LTMSG.exe" [2003-07-14 19:52 40960 C:\WINDOWS\ltmsg.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 23:37:56 217194]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 110592]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 10:20:40 233472]
MozyHome Status.lnk - C:\Program Files\MozyHome\mozystat.exe [2008-04-16 00:47:12 2311472]
TotalMedia Backup Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-06-12 04:30:12 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dllzwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\RingCentral\\RingCentral Call Controller\\RCUI.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-24 18:49]
R1 HMFAxCoreace37e6ed7bc6b8f8ec8ba8a5fc5b2b1;HMFAxCoreace37e6ed7bc6b8f8ec8ba8a5fc5b2b1;C:\WINDOWS\system32\drivers\HMFAxCoreace37e6ed7bc6b8f8ec8ba8a5fc5b2b1.sys [2007-09-01 03:28]
R1 mozyFilter;mozyFilter;C:\WINDOWS\system32\DRIVERS\mozy.sys [2008-07-14 10:25]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-24 18:48]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-07-02 14:31]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
- - - - ORPHANS REMOVED - - - -
BHO-{3F5E9987-FD12-408E-3612-018845CDF059} - (no file)
BHO-{EBF8AC57-E6F6-4041-8A3F-9F5B9E61407C} - (no file)
Toolbar-{18C388BB-5014-4906-AE38-E62BA5AA7387} - (no file)
HKLM-Run-NWEReboot - (no file)
Notify-efcbyyv - efcbyyv.dll
MSConfigStartUp-CTDrive - C:\WINDOWS\system32\drvbaz.dll
MSConfigStartUp-jihqvazg - C:\Program Files\jihqvazg\ngrehcdg.dll
MSConfigStartUp-khalypah - C:\Program Files\khalypah\cfarkpwl.dll
MSConfigStartUp-ojobmrwb - C:\Documents and Settings\All Users\Application Data\ojobmrwb.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qawgis31.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-27 03:52:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\MozyHome\mozyshell.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\FileZilla Server\FileZilla server.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\WINDOWS\system32\hpzipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-08-27 4:10:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-27 09:09:59
Pre-Run: 44,156,293,120 bytes free
Post-Run: 44,101,390,336 bytes free
236 --- E O F --- 2008-08-21 11:05:00