ComboFix 08-04-20.5 - Tony G 2008-04-21 12:56:01.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.249 [GMT -7:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Tony G\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\PAGhkUvw.ini C:\WINDOWS\system32\PAGhkUvw.ini2 . ((((((((((((((((((((((((( Files Created from 2008-03-21 to 2008-04-21 ))))))))))))))))))))))))))))))) . 2008-04-21 08:42 . 2008-04-21 08:42 d-------- C:\Documents and Settings\Tony G\Application Data\Malwarebytes 2008-04-21 08:40 . 2008-04-21 08:40 d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-04-21 08:40 . 2008-04-21 08:40 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-04-21 07:54 . 2008-04-21 07:54 d-------- C:\WINDOWS\ERUNT 2008-04-21 07:45 . 2008-04-21 08:35 d-------- C:\SDFix 2008-04-21 07:02 . 2008-04-21 07:02 5,791 --a------ C:\WINDOWS\system32\nwuhmisl.dll 2008-04-20 23:07 . 2008-04-20 23:13 10,752 --a------ C:\WINDOWS\DCEBoot.exe 2008-04-20 22:50 . 2008-02-15 23:39 138,384 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-04-20 22:50 . 2008-02-15 23:39 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys 2008-04-20 22:50 . 2008-02-15 23:39 52,240 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys 2008-04-20 22:48 . 2008-04-20 22:49 d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro 2008-04-20 22:41 . 2008-04-21 12:53 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG 2008-04-20 12:40 . 2008-04-20 22:50 d-------- C:\Program Files\Trend Micro 2008-04-20 10:04 . 2008-04-20 12:03 d-------- C:\Documents and Settings\Tony G\.housecall6.6 2008-04-20 07:02 . 2008-04-20 07:02 294 --ahs---- C:\WINDOWS\system32\inbjetco.ini 2008-04-20 01:47 . 2008-04-20 01:47 294 --ahs---- C:\WINDOWS\system32\ccpwrmup.ini 2008-04-19 23:18 . 2008-04-19 23:18 d-------- C:\Documents and Settings\All Users\Application Data\ESET 2008-04-19 21:13 . 2008-04-19 21:13 d-------- C:\Documents and Settings\Tony G\Application Data\GlarySoft 2008-04-19 20:41 . 2008-04-19 20:41 d-------- C:\WINDOWS\PC Check-up 2008-04-19 20:41 . 2008-04-19 20:57 d-------- C:\Program Files\PC Check-up 2008-04-19 19:46 . 1998-12-24 20:23 40,960 --a------ C:\WINDOWS\system32\VBAME.DLL 2008-04-19 16:43 . 2004-08-04 03:00 146,432 --a------ C:\Documents and Settings\Tony G\REGEDIT.COM 2008-04-19 16:29 . 2008-04-19 23:05 d-------- C:\Program Files\Enigma Software Group 2008-04-19 12:28 . 2008-04-19 12:28 d-------- C:\Documents and Settings\All Users\Application Data\Avira 2008-04-19 07:00 . 2008-04-19 08:35 294 --ahs---- C:\WINDOWS\system32\tkdehene.ini 2008-04-15 13:23 . 2008-04-15 13:23 d-------- C:\Program Files\Common Files\Winferno 2008-04-15 13:23 . 2008-04-15 13:23 d-------- C:\Documents and Settings\All Users\Application Data\Winferno 2008-04-15 13:23 . 2006-10-09 14:06 495,616 --a------ C:\WINDOWS\system32\WINUTIL5.DLL 2008-03-28 20:22 . 2008-03-28 20:22 87 --a------ C:\WINDOWS\cdplayer.ini . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-21 05:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-04-20 16:57 --------- d-----w C:\Program Files\Spybot - Search & Destroy 2008-04-20 06:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-04-20 05:59 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-04-20 02:32 --------- d-----w C:\Program Files\RegScrubXP 2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys 2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys 2008-03-17 03:14 4 ----a-w C:\results.bin 2008-03-16 17:24 --------- d-----w C:\Program Files\Keyword Elite 2008-03-07 01:13 --------- d-----w C:\Program Files\KeywordsAnalyzer7 2008-03-07 01:13 --------- d-----w C:\Program Files\InstantLinkPoster 2008-03-05 00:24 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-03-03 17:22 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel 2008-03-03 17:22 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel 2008-03-03 17:21 21,425 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys 2008-03-03 17:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel 2008-03-03 17:19 --------- d-----w C:\Documents and Settings\Tony G\Application Data\Intel 2008-03-02 02:58 --------- d-----w C:\Program Files\MSBuild 2008-03-02 02:54 --------- d-----w C:\Program Files\Reference Assemblies 2008-03-02 02:53 --------- d-----w C:\Program Files\MSXML 6.0 2008-02-20 21:27 286,720 ------w C:\WINDOWS\Setup1.exe 2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll 2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll 2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll 2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll 2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-02-15 09:07 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe 2008-01-13 02:40 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat 2001-08-23 20:00 557,128 ----a-w C:\Program Files\Common Files\dao360.dll 2007-10-20 20:26 23 --sha-w C:\WINDOWS\system32\bcfbcea_g.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D4F48A3-20D9-4753-85D6-3B0F700E58D6}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{177CC325-601B-46EF-9944-7887972F92EE}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{272D59DE-71B5-47D4-ABA3-1BB84822C0D6}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60E27C33-C7A9-462C-849B-67DBECA12C0C}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7DC99DC4-6D5A-4286-972C-F90822D68F9F}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94083DAA-C853-4474-B238-0F402E5BE974}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ADA17BE0-FC22-4693-8F53-27005154CB6F}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDDF4094-3ECB-43A3-A840-4895B2650223}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA6833DE-4990-4F72-94F4-934212C30C34}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F17872DD-1480-4BD4-BCEF-6C4D2FA7E3E2}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F82D3B88-681E-4228-9F5A-C5D33A16EF49}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ZipFile] @={2D7E38A6-A604-45AE-9A87-4F5F25760650} [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 14:33 155648] "PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 18:15 290816] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 05:33 122941] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 14:49 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 14:46 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 14:50 114688] "VX3000"="C:\WINDOWS\vVX3000.exe" [2006-12-05 16:38 707360] "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 11:19 819200] "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 11:17 970752] "DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 14:19 53248] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 14:50 221184] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-15 20:42 185784] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [ ] "UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-02-16 00:56 1398024] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled] "DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= R2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2007-11-22 00:11] R2 ioloSystemService;iolo System Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2007-11-22 00:11] S3 Winferno Subscription Service;Winferno Subscription Service;"C:\Program Files\Common Files\Winferno\WSS\WSS.exe" [2007-07-30 10:29] . Contents of the 'Scheduled Tasks' folder "2008-04-19 02:52:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-04-21 20:06:06 C:\WINDOWS\Tasks\PCConfidential.job" - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe "2008-04-19 16:00:00 C:\WINDOWS\Tasks\rpc.job" - C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe "2008-04-20 18:05:01 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job" - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe "2007-10-20 19:19:43 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job" - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe "2008-04-21 20:06:10 C:\WINDOWS\Tasks\WSSHelper.job" - C:\Program Files\Common Files\Winferno\WSS\WSSHelper.exe . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-21 13:07:26 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Apoint\ApntEx.exe C:\Program Files\Digital Line Detect\DLG.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe . ************************************************************************** . Completion time: 2008-04-21 13:14:59 - machine was rebooted ComboFix-quarantined-files.txt 2008-04-21 20:14:27 Pre-Run: 20,432,719,872 bytes free Post-Run: 20,463,984,640 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons 184 --- E O F --- 2008-04-10 14:19:22