ComboFix log follows-
ComboFix 08-05-27.4 - The Hoaglands 2008-05-28 14:19:50.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.201 [GMT -4:00]
Running from: C:\Documents and Settings\The Hoaglands\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\update.exe
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\start.exe
C:\WINDOWS\SYSTEM32\bbHgPqss.ini
C:\WINDOWS\SYSTEM32\bbHgPqss.ini2
C:\WINDOWS\SYSTEM32\gcfxuans.ini
C:\WINDOWS\Web\default.htt
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.
2008-05-28 03:09 . 2008-05-28 03:09 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-28 03:00 . 2008-05-27 03:12 <DIR> d-------- C:\SDFix
2008-05-28 01:24 . 2008-05-28 01:24 <DIR> d-------- C:\Deckard
2008-05-27 23:35 . 2008-05-27 23:35 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-27 23:35 . 2008-05-27 23:35 <DIR> d-------- C:\Documents and Settings\The Hoaglands\Application Data\Malwarebytes
2008-05-27 23:35 . 2008-05-27 23:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-27 23:35 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamcatchme.sys
2008-05-27 23:35 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-05-27 18:30 . 2008-05-27 18:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-27 18:07 . 2008-05-27 18:07 <DIR> d-------- C:\VundoFix Backups
2008-05-27 11:41 . 2008-05-27 11:41 <DIR> d-------- C:\Documents and Settings\The Hoaglands\Application Data\TmpRecentIcons
2008-05-27 10:35 . 2008-05-27 08:14 94,208 --a------ C:\WINDOWS\efpn.exe
2008-05-23 16:14 . 2008-05-23 16:14 45,490 --a------ C:\stream.bin
2008-05-23 15:18 . 2008-05-23 15:18 <DIR> d-------- C:\SIERRA
2008-05-23 15:16 . 2008-05-23 15:16 88 --a------ C:\WINDOWS\SIERRA.INI
2008-05-20 15:18 . 2008-05-20 15:18 <DIR> d-------- C:\Program Files\Google
2008-04-28 19:56 . 2008-04-28 19:56 <DIR> d-------- C:\Documents and Settings\The Hoaglands\Application Data\EPSON
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\SYSTEM32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\SYSTEM32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\SYSTEM32\dllcache\win32k.sys
2008-03-01 22:36 3,591,680 ----a-w C:\WINDOWS\SYSTEM32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\SYSTEM32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\SYSTEM32\dllcache\iexplore.exe
2005-09-14 20:53 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050914_205300.sql
2005-08-13 15:06 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050813_150631.sql
2005-06-23 17:20 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050623_172054.sql
2005-05-28 01:54 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050528_015443.sql
2005-03-26 19:20 21 ----a-w C:\Program Files\AVPersonalAVWIN.INI
2005-03-11 16:16 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050311_171640.sql
2005-02-25 21:42 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050225_224200.sql
2005-02-25 17:10 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050225_181034.sql
2005-02-25 15:32 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20050225_163254.sql
2004-08-12 05:37 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20040812_053744.sql
2004-05-31 12:58 37,634 ----a-w C:\Documents and Settings\The Hoaglands\raw101.exe
2004-04-19 20:34 0 ----a-w C:\Program Files\GeacInterealtyDS_HFD_596266616_20040419_203424.sql
2004-03-29 16:04 131,072 ----a-w C:\Program Files\fsuninst.ENG
2003-03-07 01:17 2,765 ----a-w C:\Program Files\Common Files\AutoUpdate.rtf
2003-01-27 15:50 1,000,448 ----a-w C:\Program Files\Common Files\AutoUpdate.exe
2002-03-29 23:18 266 --sh--w C:\Program Files\desktop.ini
2002-03-29 23:18 11,079 ---h--w C:\Program Files\folder.htt
2002-02-08 17:13 8,527,672 ----a-w C:\Program Files\PLuSExpress.exe
2001-11-17 00:25 73,728 ----a-w C:\Documents and Settings\The Hoaglands\Setup.exe
2001-11-17 00:25 650 ----a-w C:\Documents and Settings\The Hoaglands\LAYOUT.BIN
2001-11-17 00:25 450 ----a-w C:\Documents and Settings\The Hoaglands\OS.DAT
2001-11-17 00:25 34,816 ----a-w C:\Documents and Settings\The Hoaglands\_Setup.dll
2001-11-17 00:25 27,648 ----a-w C:\Documents and Settings\The Hoaglands\_ISDel.exe
2001-11-17 00:25 23,541 ----a-w C:\Documents and Settings\The Hoaglands\LANG.DAT
2001-10-16 17:48 51,072 ----a-w C:\Documents and Settings\The Hoaglands\EUSBMSD.sys
2004-11-20 17:16 1,682 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
2004-11-20 17:16 56 --sh--r C:\WINDOWS\SYSTEM32\8DCA1CC71F.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@={7D688A77-C613-11D0-999B-00C04FD655E1}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-19 16:00 262401]
"Auto EPSON Stylus CX3800 Series on DISH"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2005-02-07 23:00 98304]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
"{27796771-8D05-4EE6-B478-43CE759F2106}"= C:\WINDOWS\system32\rqRJYrRj.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=NVDESK32.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.UV12"= aoxdxipl.ax
"VIDC.I263"= i263_32.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
d-a------ 2001-12-10 18:40 0 C:\WINDOWS\System32\
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a------ 2007-10-30 20:07 140568 C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
--a------ 2007-10-30 20:11 909208 C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVSCHED32]
C:\Program Files\AVPersonal\AVSched32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDefender Antivirus]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 03:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EM_EXEC]
--a------ 2000-03-03 09:00 33792 C:\Program Files\Logitech\MouseWare\System\em_exec.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
--a------ 2005-02-07 23:00 98304 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FAST Defrag]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-09-12 01:58 229952 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launcher]
C:\Program Files\KFH\cl\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware Reboot]
--a------ 2008-05-05 20:46 1179256 C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-08-12 00:43 7630848 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-08-12 00:43 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-08-12 00:43 1519616 C:\WINDOWS\SYSTEM32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-09-01 15:57 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run StartupMonitor]
--a------ 2000-05-20 17:23 86016 C:\WINDOWS\StartupMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecretSmileys]
C:\PROGRA~1\SECRET~1\ss.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-03-25 04:28 144784 C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2007-06-21 14:06 1318912 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2005-04-02 15:39 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
--a------ 2007-10-31 12:53 2595616 C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SaveNow"=C:\Program Files\SaveNow\SaveNow.exe
"b3dUpdate"=C:\WINDOWS\BDE\Update\Zupdate.EXE -silent -p "C:\WINDOWS\BDE\Update" -s setup.cab
"New.net Startup"=rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"PP2000 Taskbar Control"=C:\Program Files\Protector Plus\PPTbc.EXE
"PP2000 Real-time Scan"=C:\Program Files\Protector Plus\PPVstop.exe
"PP2000 InstaUpdate"=C:\Program Files\Protector Plus\PPInupdt.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\REAL\\RealOne Player\\REALPLAY.EXE"=
"C:\\Program Files\\Windows Media Player\\WMPLAYER.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\WINDOWS\\System32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\drivers\avgntmgr.sys [2008-04-19 16:00]
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-02-01 20:28]
R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys [2008-04-19 16:00]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-04 04:47]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-04 03:40]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-10-31 13:19]
S3 Aox402Camera;GD-350V;C:\WINDOWS\system32\DRIVERS\aox402vc.sys [2002-01-16 01:33]
S3 PPDrv;Protector Plus Driver;C:\Program Files\Protector Plus\PPDrv.sys []
S3 SE402RefCameraStill;Concord Eye-Q Mini (WDM);C:\WINDOWS\system32\DRIVERS\aox402sc.sys [2001-11-20 13:58]
S4 lkbdfltr;Logitech Keyboard Class Filter Driver;C:\WINDOWS\system32\DRIVERS\lkbdfltr.sys [2000-03-03 09:00]
S4 lmoufltr;Logitech Mouse Class Filter Driver;C:\WINDOWS\system32\DRIVERS\lmoufltr.sys [2000-03-03 09:00]
S4 lsermous;Logitech Serial Mouse Driver;C:\WINDOWS\system32\DRIVERS\lsermous.sys [2000-03-03 09:00]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msimn.inf,User.Install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msimn.inf,User.Install
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2008-05-28 13:10:16 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2002-04-10 01:09:22 C:\WINDOWS\Tasks\Maintenance-Defragment programs.job"
- C:\WINDOWS\DEFRAG.EXE
"2008-05-28 13:10:16 C:\WINDOWS\Tasks\Maintenance-Disk cleanup.job"
- C:\WINDOWS\CLEANMGR.EXE
"2008-05-28 18:00:02 C:\WINDOWS\Tasks\AB2FE87F91849E5B.job"
- c:\progra~1\stylef~1\DrvLiveOption.exe
"2006-11-03 15:00:02 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-28 14:27:03
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\COMMON FILES\ACRONIS\SCHEDULE2\SCHEDUL2.EXE
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-05-28 14:29:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-28 18:29:32
Pre-Run: 41,966,632,960 bytes free
Post-Run: 41,885,335,552 bytes free
227 --- E O F --- 2008-05-28 07:01:15