ComboFix 09-01-13.04 - Francesca Tolchin 2009-01-14 19:40:13.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1015.625 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: F:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\drivers\rbvwqxppusba.sys
c:\windows\Tasks\rpvidrmj.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\rbvwqxppusba.sys
c:\windows\Tasks\rpvidrmj.job
.
((((((((((((((((((((((((( Files Created from 2008-12-15 to 2009-01-15 )))))))))))))))))))))))))))))))
.
2009-01-12 11:36 . 2009-01-12 11:36
d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-12 11:36 . 2009-01-12 11:36 d-------- c:\documents and settings\Francesca Tolchin\Application Data\Malwarebytes
2009-01-12 11:36 . 2009-01-12 11:36 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-12 11:36 . 2009-01-04 18:38 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-12 11:36 . 2009-01-04 18:38 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-10 17:12 . 2009-01-10 17:12 d-------- c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-01-05 21:50 . 2009-01-05 21:50 d-------- c:\program files\CCleaner
2009-01-03 17:32 . 2009-01-03 17:37 d-------- c:\program files\Spybot - Search & Destroy
2009-01-03 17:32 . 2009-01-05 22:27 d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-02 16:55 . 2009-01-02 16:55 d-------- C:\VundoFix Backups
2009-01-02 16:12 . 2009-01-03 15:15 d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-01-02 15:29 . 2009-01-12 11:35 d--h----- C:\$AVG8.VAULT$
2009-01-02 15:18 . 2009-01-14 19:23 d-------- c:\windows\system32\drivers\Avg
2009-01-02 15:18 . 2009-01-05 12:19 d-------- c:\documents and settings\Francesca Tolchin\Application Data\AVGTOOLBAR
2009-01-02 15:18 . 2009-01-02 15:18 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-01-02 15:18 . 2009-01-02 15:18 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-01-02 15:18 . 2009-01-02 15:18 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-01-02 15:17 . 2009-01-02 15:17 d-------- c:\program files\AVG
2009-01-02 15:17 . 2009-01-02 15:28 d-------- c:\documents and settings\All Users\Application Data\avg8
2009-01-02 13:23 . 2009-01-02 13:23 d-------- c:\documents and settings\Francesca Tolchin\Pavark
2009-01-01 15:19 . 2009-01-01 15:20 47,593 --a------ c:\windows\system32\zctqvqdfgaittpqfk.exe
2008-12-31 14:07 . 2008-12-31 14:07 d-------- c:\documents and settings\Administrator\Application Data\Intel
2008-12-29 21:38 . 2005-07-28 12:40 d-------- c:\documents and settings\Administrator\WINDOWS
2008-12-29 21:38 . 2005-07-28 13:21 d-------- c:\documents and settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-12-29 21:38 . 2005-07-28 13:08 d-------- c:\documents and settings\Administrator\Application Data\toshiba
2008-12-29 21:38 . 2005-07-28 13:15 d-------- c:\documents and settings\Administrator\Application Data\Intuit
2008-12-29 21:38 . 2005-07-28 13:14 d-------- c:\documents and settings\Administrator\Application Data\InterTrust
2008-12-29 21:38 . 2006-02-28 14:46 d-------- c:\documents and settings\Administrator\Application Data\AOL
2008-12-29 21:38 . 2008-12-29 21:38 d-------- c:\documents and settings\Administrator
2008-12-22 23:15 . 2008-12-25 10:32 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-22 23:15 . 2008-12-22 23:15 1,409 --a------ c:\windows\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 06:16 --------- d-----w c:\program files\Notebook Maximizer
2009-01-06 06:14 --------- d-----w c:\program files\Pure Networks
2009-01-06 06:03 --------- d-----w c:\program files\Microsoft Works
2009-01-06 06:00 --------- d-----w c:\program files\QuickTime
2009-01-06 06:00 --------- d-----w c:\program files\OfficeUpdate11
2009-01-06 06:00 --------- d-----w c:\program files\Lavasoft
2009-01-06 06:00 --------- d-----w c:\program files\Common Files\aolshare
2009-01-06 06:00 --------- d-----w c:\program files\Common Files\AOL
2009-01-06 06:00 --------- d-----w c:\program files\Apple Software Update
2009-01-06 06:00 --------- d-----w c:\program files\America Online 9.0
2009-01-02 22:52 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee.com
2009-01-02 01:25 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-30 05:14 --------- d-----w c:\documents and settings\Francesca Tolchin\Application Data\Move Networks
2008-12-28 07:01 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-08 17:21 --------- d-----w c:\program files\Yahoo!
2008-12-08 17:21 --------- d-----w c:\program files\Common Files\SureThing Shared
2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-22 18:34 186 ----a-w c:\documents and settings\Francesca Tolchin\Application Data\wklnhst.dat
2008-10-16 22:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 22:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 22:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-23 04:30 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-23 04:30 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-23 04:30 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-23 04:30 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-23 04:30 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-12_12.53.10.90 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-29 65536]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"MindfulClock"="c:\program files\MindfulClock\Mfclock.exe" [2006-04-10 436736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 73728]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2005-08-10 356352]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 122880]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 151552]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-07 114688]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 1077301]
"Notebook Maximizer"="c:\program files\Notebook Maximizer\maximizer_startup.exe" [2006-05-04 40960]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-04-12 184320]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-09-12 229952]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-07 94208]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-07 77824]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-02 1261336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"TPSMain"="TPSMain.exe" [2005-05-31 c:\windows\system32\TPSMain.exe]
"TFncKy"="TFncKy.exe" [BU]
"NDSTray.exe"="NDSTray.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 c:\windows\agrsmmsg.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2005-10-25 82026]
AutoCAD LT Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-03-05 11000]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 53248]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-07-28 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 10:27 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\WINDOWS\\system32\\TPSMain.exe"=
"c:\\Program Files\\TOSHIBA\\TOSHIBA Applet\\THotkey.exe"=
"c:\\Program Files\\TOSHIBA\\ConfigFree\\NDSTray.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-02 97928]
R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-02 875288]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-02 231704]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-02 76040]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{331cb1d0-0ffb-11dd-81c7-0013ce4b051e}]
\Shell\AutoRun\command - E:\Autorun.exe /run
\Shell\Shell00\Command - E:\Autorun.exe /run
\Shell\Shell01\Command - E:\Autorun.exe /action
\Shell\Shell02\Command - E:\Autorun.exe /uninstall
.
Contents of the 'Scheduled Tasks' folder
2008-12-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 13:21]
.
.
------- Supplementary Scan -------
.
uStart Page = www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Francesca Tolchin\Application Data\Mozilla\Firefox\Profiles\hrg2vvec.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www10.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Yoog Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?source=mpues&hl=en
FF - prefs.js: keyword.URL - hxxp://www10.yoog.com/search.php?q=
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL - hxxp://www10.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www10.yoog.com/search.php?q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 19:41:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1008)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2009-01-14 19:42:40
ComboFix-quarantined-files.txt 2009-01-15 03:42:33
ComboFix2.txt 2009-01-15 03:37:10
ComboFix3.txt 2009-01-12 20:53:56
Pre-Run: 80,677,568,512 bytes free
Post-Run: 80,664,002,560 bytes free
204 --- E O F --- 2008-12-19 04:54:36