Here is the log:
ComboFix 09-06-23.01 - root 06/28/2009 10:12.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1517 [GMT -4:00]
Running from: c:\documents and settings\root.CHANGEME\Desktop\Columbo.exe
Command switches used :: c:\documents and settings\root.CHANGEME\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\17290784
c:\documents and settings\All Users\Application Data\97300776
c:\documents and settings\All Users\Application Data\17290784\17290784.glu
c:\documents and settings\All Users\Application Data\17290784\pc17290784cnf
c:\documents and settings\All Users\Application Data\17290784\pc17290784ins
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 )))))))))))))))))))))))))))))))
.
2009-06-25 01:37 . 2009-06-25 01:37 -------- dc----w- c:\windows\system32\dllcache\cache
2009-06-23 04:56 . 2009-06-23 05:16 -------- d-----w- C:\New
2009-06-18 00:45 . 2009-06-18 00:45 -------- d-----w- c:\program files\Trend Micro
2009-06-18 00:33 . 2009-06-18 00:33 1033728 -c--a-w- c:\windows\system32\dllcache\explorer.exe
2009-06-18 00:33 . 2009-06-18 00:33 1033728 ----a-w- c:\windows\Explorer.EXE
2009-06-17 21:18 . 2009-06-27 22:52 -------- d-----w- c:\program files\WinClamAVShield
2009-06-17 21:16 . 2009-06-25 16:03 -------- d-----w- c:\documents and settings\root.CHANGEME\Application Data\Spyware Terminator
2009-06-17 21:16 . 2009-06-17 21:16 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2009-06-17 21:16 . 2009-06-17 21:16 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2009-06-17 21:16 . 2009-06-17 21:16 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-06-17 21:16 . 2009-06-27 02:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-06-17 21:16 . 2009-06-25 00:34 -------- d-----w- c:\program files\Spyware Terminator
2009-06-17 21:12 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 21:12 . 2009-06-17 21:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-17 21:12 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-17 20:11 . 2009-06-25 02:52 -------- d-----w- c:\program files\a-squared Free
2009-06-17 19:00 . 2009-06-17 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-17 18:50 . 2009-06-17 18:50 2052888 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-17 18:50 . 2009-06-17 12:11 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-17 18:50 . 2009-06-17 12:11 27784 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmfx86.sys
2009-06-17 18:50 . 2009-06-17 12:11 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-17 18:50 . 2009-06-17 12:11 1261344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-17 18:50 . 2009-06-17 12:11 1452312 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-17 12:28 . 2009-06-20 16:33 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-17 12:11 . 2009-06-17 12:11 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-17 12:11 . 2009-06-17 12:11 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-17 12:11 . 2009-06-17 12:11 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-17 12:11 . 2009-06-17 18:50 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-17 12:11 . 2009-06-24 14:43 -------- d-----w- c:\windows\system32\drivers\Avg
2009-06-17 12:11 . 2009-06-17 12:11 -------- d-----w- c:\program files\AVG
2009-05-31 19:51 . 2009-05-31 19:51 -------- d-----w- c:\documents and settings\root.CHANGEME\Local Settings\Application Data\Help
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 15:10 . 2005-01-29 01:48 66640 -c--a-w- c:\documents and settings\root.CHANGEME\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-25 02:52 . 2005-08-05 18:00 -------- d-----w- c:\documents and settings\hpiccari\Application Data\Lavasoft
2009-06-25 01:04 . 2009-01-07 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-17 19:10 . 2007-07-20 13:20 -------- d-----w- c:\program files\McAfee
2009-06-17 12:08 . 2009-01-21 21:18 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-31 19:45 . 2005-10-25 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\yahoo!
2009-05-31 19:45 . 2005-10-25 17:31 -------- d-----w- c:\program files\Yahoo!
2009-05-31 19:44 . 2009-04-21 14:07 -------- d-----w- c:\program files\LightSpeed
2009-05-29 00:50 . 2004-03-11 17:56 -------- d-----w- c:\documents and settings\root.CHANGEME\Application Data\AdobeUM
2009-05-24 23:23 . 2009-05-24 23:23 136 ----a-w- c:\documents and settings\root.CHANGEME\Local Settings\Application Data\fusioncache.dat
2009-05-22 01:31 . 2009-05-25 03:16 607472 ----a-w- c:\documents and settings\All Users\Application Data\yahoo!\YUpdater\yupdater.exe
2009-05-19 00:10 . 2009-05-19 00:10 -------- d-----w- c:\documents and settings\root.CHANGEME\Application Data\InstallShield Installation Information
2009-05-19 00:10 . 2009-05-19 00:10 -------- d-----w- c:\documents and settings\root.CHANGEME\Application Data\2K Games
2009-05-19 00:08 . 2009-05-19 00:08 -------- d-----w- c:\documents and settings\root.CHANGEME\Application Data\InstallShield
2009-05-07 20:57 . 2009-05-07 20:57 -------- d-----w- c:\program files\Lexmark X74-X75
2009-04-30 05:01 . 2009-04-30 05:01 -------- d-----w- c:\documents and settings\root.CHANGEME\Application Data\Lavasoft
.
((((((((((((((((((((((((((((( SnapShot@2009-06-25_01.31.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-25 01:37 . 2007-04-17 02:45 53080 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-25 01:37 . 2008-04-14 09:42 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-25 01:37 . 2008-04-14 09:42 26112 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-25 01:37 . 2008-04-14 09:42 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-25 01:37 . 2008-04-14 09:42 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-25 01:37 . 2008-04-14 09:42 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-25 01:37 . 2008-04-14 09:42 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-25 01:37 . 2008-04-14 04:09 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-25 01:37 . 2008-04-14 04:23 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-25 01:37 . 2008-04-14 09:42 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2004-02-20 03:04 . 2009-06-27 22:49 245512 c:\windows\system32\FNTCACHE.DAT
+ 2009-06-25 01:37 . 2008-04-14 09:42 507904 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-25 01:37 . 2008-04-14 09:42 666112 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-25 01:37 . 2008-04-14 09:42 578560 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-25 01:37 . 2008-04-14 09:42 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-25 01:37 . 2008-04-14 04:50 361344 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-25 01:37 . 2008-04-14 09:42 108544 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-25 01:37 . 2008-04-14 04:50 182656 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-25 01:37 . 2008-04-14 09:41 989696 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-25 01:37 . 2008-04-14 09:41 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-25 01:37 . 2008-04-14 09:41 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-06-25 01:37 . 2008-04-14 09:42 1614848 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-25 01:37 . 2008-04-14 04:57 2188928 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-25 01:37 . 2008-04-14 04:01 2065792 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-25 01:37 . 2009-06-18 00:33 1033728 c:\windows\system32\dllcache\cache\Explorer.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-08-01 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-08-01 618496]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UdaterUI.exe" [2007-03-27 136768]
"TpHotkey"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-01-15 94208]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-20 32881]
"QCWLIcon"="c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2003-07-30 53248]
"BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2004-02-05 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-02-05 395264]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-02-05 106496]
"eFax 4.3"="c:\program files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 116224]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-14 169984]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-06-17 2174464]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2003-09-04 77824]
"Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2003-11-20 57344]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
eFax 4.3.lnk - c:\program files\eFax Messenger 4.3\J2GTray.exe [2007-8-15 629248]
HOTSYNCSHORTCUTNAME.lnk - c:\program files\Palm\Hotsync.exe [2004-6-9 471040]
TIBCO Software Inc. VPN Client.lnk - c:\program files\Cisco Systems\VPN 3000 Client\ipsecdialer.exe [2004-4-28 1269836]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-17 12:11 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1469188156-960889200-926709054-21729\Scripts\Logon\0\0]
"Script"=mcafee.cmd
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)
"MDM"=2 (0x2)
"McAfeeFramework"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"a2free"=2 (0x2)
"cisvc"=3 (0x3)
"LexBceS"=2 (0x2)
"avg8wd"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\FSRremoS.EXE"=
"c:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\AcroRd32.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\root.CHANGEME\\Application Data\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Complete\\Civilization4.exe"=
"c:\\Documents and Settings\\root.CHANGEME\\Application Data\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Complete\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Documents and Settings\\root.CHANGEME\\Application Data\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Complete\\Warlords\\Civ4Warlords.exe"=
"c:\\WINDOWS\\system32\\TpShocks.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2/19/2004 6:11 PM 52136]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/17/2009 8:11 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/17/2009 8:11 AM 108552]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [6/17/2009 5:16 PM 142592]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2/19/2004 7:08 PM 15360]
R2 CVPNDRV;TIBCO Software Inc. IPsec Driver;c:\windows\system32\drivers\CVPNDrv.sys [4/28/2004 6:28 PM 263751]
R2 PPNT;PPNT;c:\windows\system32\drivers\ppnt.sys [8/3/2005 7:10 PM 13824]
R2 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2/19/2004 6:11 PM 4225]
S3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family Driver;c:\windows\system32\drivers\cben5.sys [2/23/2004 5:36 PM 46108]
S3 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMOUSE.SYS [6/7/2004 12:30 PM 16384]
S3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\drivers\pelusblf.sys [6/7/2004 12:30 PM 9216]
S3 WPC11;Instant Wireless Network PC Card V3.0 Driver;c:\windows\system32\drivers\LSWLNDS.sys [8/5/2005 11:18 AM 54083]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/17/2009 8:11 AM 298776]
.
Contents of the 'Scheduled Tasks' folder
2009-06-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-06-28 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2004-02-19 09:36]
.
.
------- Supplementary Scan -------
.
mStart Page =
hxxp://www.yahoo.com/mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/def ... earch.htmluInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: google.com
Trusted Zone: youtube.com
FF - ProfilePath -
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1020)
c:\windows\system32\CSGina.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\iphlpapi.dll
.
Completion time: 2009-06-28 10:17
ComboFix-quarantined-files.txt 2009-06-28 14:17
ComboFix2.txt 2009-06-25 03:27
ComboFix3.txt 2009-06-25 01:38
Pre-Run: 49,207,021,568 bytes free
Post-Run: 49,196,978,176 bytes free
226 --- E O F --- 2009-06-25 16:02