ComboFix 08-04-20.5 - Tony G 2008-04-21 12:56:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.249 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tony G\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\PAGhkUvw.ini
C:\WINDOWS\system32\PAGhkUvw.ini2
.
((((((((((((((((((((((((( Files Created from 2008-03-21 to 2008-04-21 )))))))))))))))))))))))))))))))
.
2008-04-21 08:42 . 2008-04-21 08:42
d-------- C:\Documents and Settings\Tony G\Application Data\Malwarebytes
2008-04-21 08:40 . 2008-04-21 08:40 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-21 08:40 . 2008-04-21 08:40 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-21 07:54 . 2008-04-21 07:54 d-------- C:\WINDOWS\ERUNT
2008-04-21 07:45 . 2008-04-21 08:35 d-------- C:\SDFix
2008-04-21 07:02 . 2008-04-21 07:02 5,791 --a------ C:\WINDOWS\system32\nwuhmisl.dll
2008-04-20 23:07 . 2008-04-20 23:13 10,752 --a------ C:\WINDOWS\DCEBoot.exe
2008-04-20 22:50 . 2008-02-15 23:39 138,384 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-04-20 22:50 . 2008-02-15 23:39 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys
2008-04-20 22:50 . 2008-02-15 23:39 52,240 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys
2008-04-20 22:48 . 2008-04-20 22:49 d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-04-20 22:41 . 2008-04-21 12:53 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG
2008-04-20 12:40 . 2008-04-20 22:50 d-------- C:\Program Files\Trend Micro
2008-04-20 10:04 . 2008-04-20 12:03 d-------- C:\Documents and Settings\Tony G\.housecall6.6
2008-04-20 07:02 . 2008-04-20 07:02 294 --ahs---- C:\WINDOWS\system32\inbjetco.ini
2008-04-20 01:47 . 2008-04-20 01:47 294 --ahs---- C:\WINDOWS\system32\ccpwrmup.ini
2008-04-19 23:18 . 2008-04-19 23:18 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-04-19 21:13 . 2008-04-19 21:13 d-------- C:\Documents and Settings\Tony G\Application Data\GlarySoft
2008-04-19 20:41 . 2008-04-19 20:41 d-------- C:\WINDOWS\PC Check-up
2008-04-19 20:41 . 2008-04-19 20:57 d-------- C:\Program Files\PC Check-up
2008-04-19 19:46 . 1998-12-24 20:23 40,960 --a------ C:\WINDOWS\system32\VBAME.DLL
2008-04-19 16:43 . 2004-08-04 03:00 146,432 --a------ C:\Documents and Settings\Tony G\REGEDIT.COM
2008-04-19 16:29 . 2008-04-19 23:05 d-------- C:\Program Files\Enigma Software Group
2008-04-19 12:28 . 2008-04-19 12:28 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-19 07:00 . 2008-04-19 08:35 294 --ahs---- C:\WINDOWS\system32\tkdehene.ini
2008-04-15 13:23 . 2008-04-15 13:23 d-------- C:\Program Files\Common Files\Winferno
2008-04-15 13:23 . 2008-04-15 13:23 d-------- C:\Documents and Settings\All Users\Application Data\Winferno
2008-04-15 13:23 . 2006-10-09 14:06 495,616 --a------ C:\WINDOWS\system32\WINUTIL5.DLL
2008-03-28 20:22 . 2008-03-28 20:22 87 --a------ C:\WINDOWS\cdplayer.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-21 05:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-20 16:57 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-20 06:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-20 05:59 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-20 02:32 --------- d-----w C:\Program Files\RegScrubXP
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-17 03:14 4 ----a-w C:\results.bin
2008-03-16 17:24 --------- d-----w C:\Program Files\Keyword Elite
2008-03-07 01:13 --------- d-----w C:\Program Files\KeywordsAnalyzer7
2008-03-07 01:13 --------- d-----w C:\Program Files\InstantLinkPoster
2008-03-05 00:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-03 17:22 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-03-03 17:22 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel
2008-03-03 17:21 21,425 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-03-03 17:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-03-03 17:19 --------- d-----w C:\Documents and Settings\Tony G\Application Data\Intel
2008-03-02 02:58 --------- d-----w C:\Program Files\MSBuild
2008-03-02 02:54 --------- d-----w C:\Program Files\Reference Assemblies
2008-03-02 02:53 --------- d-----w C:\Program Files\MSXML 6.0
2008-02-20 21:27 286,720 ------w C:\WINDOWS\Setup1.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 09:07 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2008-01-13 02:40 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2001-08-23 20:00 557,128 ----a-w C:\Program Files\Common Files\dao360.dll
2007-10-20 20:26 23 --sha-w C:\WINDOWS\system32\bcfbcea_g.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D4F48A3-20D9-4753-85D6-3B0F700E58D6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{177CC325-601B-46EF-9944-7887972F92EE}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{272D59DE-71B5-47D4-ABA3-1BB84822C0D6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60E27C33-C7A9-462C-849B-67DBECA12C0C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7DC99DC4-6D5A-4286-972C-F90822D68F9F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94083DAA-C853-4474-B238-0F402E5BE974}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ADA17BE0-FC22-4693-8F53-27005154CB6F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDDF4094-3ECB-43A3-A840-4895B2650223}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA6833DE-4990-4F72-94F4-934212C30C34}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F17872DD-1480-4BD4-BCEF-6C4D2FA7E3E2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F82D3B88-681E-4228-9F5A-C5D33A16EF49}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ZipFile]
@={2D7E38A6-A604-45AE-9A87-4F5F25760650}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 14:33 155648]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 18:15 290816]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 05:33 122941]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 14:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 14:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 14:50 114688]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-12-05 16:38 707360]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 11:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 11:17 970752]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 14:19 53248]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 14:50 221184]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-15 20:42 185784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [ ]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-02-16 00:56 1398024]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2007-11-22 00:11]
R2 ioloSystemService;iolo System Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2007-11-22 00:11]
S3 Winferno Subscription Service;Winferno Subscription Service;"C:\Program Files\Common Files\Winferno\WSS\WSS.exe" [2007-07-30 10:29]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-19 02:52:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-21 20:06:06 C:\WINDOWS\Tasks\PCConfidential.job"
- C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
"2008-04-19 16:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
"2008-04-20 18:05:01 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-10-20 19:19:43 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-04-21 20:06:10 C:\WINDOWS\Tasks\WSSHelper.job"
- C:\Program Files\Common Files\Winferno\WSS\WSSHelper.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-21 13:07:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2008-04-21 13:14:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-21 20:14:27
Pre-Run: 20,432,719,872 bytes free
Post-Run: 20,463,984,640 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
184 --- E O F --- 2008-04-10 14:19:22