ComboFix 08-09-04.09 - Compaq_Owner 2008-09-05 16:12:11.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.174 [GMT -7:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Guest\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\oi\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\msconfigs
C:\Program Files\XP Antivirus
C:\Program Files\XP Antivirus\xpa.exe
C:\WINDOWS\eslb.exe
C:\WINDOWS\ksendlbttla.dll
C:\WINDOWS\neltabxw.exe
C:\WINDOWS\vrmdtneg.dll
C:\WINDOWS\xvorfwbd.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-05 to 2008-09-05 )))))))))))))))))))))))))))))))
.
2008-09-05 14:20 . 2008-09-05 14:20 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-09-05 13:55 . 2008-09-05 13:55 <DIR> d-------- C:\Program Files\AskSBar
2008-09-05 13:55 . 2008-09-05 13:55 249,592 --a------ C:\WINDOWS\system32\cssdll32.dll
2008-09-05 13:54 . 2008-09-05 13:54 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Comodo
2008-09-05 13:54 . 2008-09-05 13:54 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-09-05 13:54 . 2008-09-05 13:54 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-09-05 13:54 . 2008-09-05 13:54 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-09-05 13:33 . 2008-09-05 13:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-04 17:24 . 2008-09-04 17:24 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Talkback
2008-09-04 17:19 . 2004-08-04 05:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-09-04 17:19 . 2008-09-04 17:19 1,849 -rahs---- C:\WINDOWS\system32\drivers\103C_HP_CPC_PP158AA-ABA SR1320NX NA510_YC_0Pres_QCNH448_E51NAheRED3_47_I
Salmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M448
_J80_7AMD_8Sempron_91.81_#050226_N10390900_Z11C1048C_G10396330.MRK
2008-09-04 17:18 . 2004-10-20 07:47 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\WINDOWS
2008-09-04 17:18 . 2004-10-21 03:13 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
2008-09-04 17:18 . 2004-10-20 23:40 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Sonic
2008-09-04 17:18 . 2004-10-20 23:40 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SampleView
2008-09-04 17:18 . 2004-10-20 07:31 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Intervideo
2008-09-04 17:18 . 2004-10-20 07:47 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2008-09-04 17:18 . 2008-09-05 16:06 <DIR> d-------- C:\Documents and Settings\Compaq_Owner
2008-09-04 17:15 . 2004-10-20 07:47 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-04 17:14 . 2003-09-10 23:36 21,060 --------- C:\WINDOWS\system32\drivers\iviaspi.sys
2008-09-04 17:14 . 2003-09-19 01:47 10,368 --------- C:\WINDOWS\system32\drivers\pfc.sys
2008-09-04 17:09 . 2008-09-04 17:10 <DIR> d-------- C:\Program Files\SiS VGA Utilities V3.63
2008-09-04 17:02 . 2004-08-03 23:10 61,056 --a------ C:\WINDOWS\system32\drivers\ohci1394.sys
2008-09-04 17:02 . 2004-08-03 23:10 53,248 --a------ C:\WINDOWS\system32\drivers\1394bus.sys
2008-09-04 17:02 . 2004-08-03 22:58 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-09-04 17:02 . 2001-08-17 13:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2008-09-04 17:02 . 2004-08-03 22:58 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-09-04 17:02 . 2004-08-03 22:58 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-09-04 17:01 . 2008-09-04 17:09 <DIR> d-------- C:\WINDOWS\system32\trayres
2008-09-04 17:01 . 2004-09-24 02:47 331,776 --a------ C:\WINDOWS\system32\sistray.exe
2008-09-04 17:01 . 2004-09-24 09:44 184,320 --------- C:\WINDOWS\system32\SiSApCom.dll
2008-09-04 17:01 . 2004-09-24 09:49 110,592 --------- C:\WINDOWS\system32\TVMode.dll
2008-09-04 16:39 . 2008-09-04 16:48 <DIR> dr-h----- C:\MSOCache
2008-09-04 16:37 . 2008-09-04 17:17 <DIR> dr-hsc--- C:\WINDOWS\system32\dllcache
2008-09-04 11:30 . 2008-09-04 11:30 <DIR> d-------- C:\WINDOWS\privacy_danger
2008-09-04 11:11 . 2008-09-04 11:11 <DIR> d-------- C:\Program Files\Foxit Software
2008-09-04 08:04 . 2008-09-04 08:05 296,462 --a------ C:\WINDOWS\~DFE6AE.tmp
2008-09-03 17:36 . 2008-09-03 17:36 296,462 --a------ C:\WINDOWS\~DF2FDF.tmp
2008-09-03 17:34 . 2008-09-03 17:35 296,462 --a------ C:\WINDOWS\~DFCE9C.tmp
2008-09-03 15:43 . 2008-09-03 15:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-03 15:42 . 2008-09-03 17:32 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-03 12:12 . 2008-09-03 12:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-03 12:11 . 2008-09-03 12:11 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-01 14:17 . 2008-09-01 14:17 <DIR> d-------- C:\TEMP
2008-09-01 14:17 . 2008-09-01 14:17 <DIR> d-------- C:\Sun
2008-08-30 10:51 . 2008-08-30 10:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-30 10:49 . 2008-08-30 10:49 <DIR> d-------- C:\Program Files\Yahoo!
2008-08-30 10:49 . 2008-08-30 10:49 <DIR> d-------- C:\Program Files\GamingSquared
2008-08-30 10:49 . 2008-08-30 10:49 <DIR> d-------- C:\Program Files\7-Zip
2008-08-30 10:49 . 2008-08-30 10:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GamingSquared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-05 23:09 --------- d-----w C:\Program Files\Symantec
2008-09-05 23:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-05 23:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-09-05 20:55 --------- d-----w C:\Program Files\Comodo
2008-09-05 00:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-09-05 00:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-04 20:30 90,112 ----a-w C:\WINDOWS\DUMP32b8.tmp
2008-09-04 20:28 90,112 ----a-w C:\WINDOWS\DUMP4d74.tmp
2008-09-04 20:27 90,112 ----a-w C:\WINDOWS\DUMP53c2.tmp
2008-09-04 20:26 90,112 ----a-w C:\WINDOWS\DUMP53c1.tmp
2008-09-04 20:25 90,112 ----a-w C:\WINDOWS\DUMP5303.tmp
2008-09-04 20:23 90,112 ----a-w C:\WINDOWS\DUMP4dd1.tmp
2008-09-04 20:22 90,112 ----a-w C:\WINDOWS\DUMP52b3.tmp
2008-09-04 20:19 90,112 ----a-w C:\WINDOWS\DUMP53ad.tmp
2008-09-04 20:18 90,112 ----a-w C:\WINDOWS\DUMP543a.tmp
2008-09-04 20:17 90,112 ----a-w C:\WINDOWS\DUMP5498.tmp
2008-09-04 20:15 90,112 ----a-w C:\WINDOWS\DUMP5342.tmp
2008-09-04 20:14 90,112 ----a-w C:\WINDOWS\DUMP5360.tmp
2008-09-04 20:13 90,112 ----a-w C:\WINDOWS\DUMP53c0.tmp
2008-09-04 20:11 90,112 ----a-w C:\WINDOWS\DUMP52e4.tmp
2008-09-04 20:10 90,112 ----a-w C:\WINDOWS\DUMP52d5.tmp
2008-09-04 20:09 90,112 ----a-w C:\WINDOWS\DUMP53bf.tmp
2008-09-04 20:07 90,112 ----a-w C:\WINDOWS\DUMP53cd.tmp
2008-09-04 20:06 90,112 ----a-w C:\WINDOWS\DUMP52e3.tmp
2008-09-04 20:03 90,112 ----a-w C:\WINDOWS\DUMP5351.tmp
2008-09-04 20:01 90,112 ----a-w C:\WINDOWS\DUMP5323.tmp
2008-09-04 19:59 90,112 ----a-w C:\WINDOWS\DUMP5322.tmp
2008-09-04 19:58 90,112 ----a-w C:\WINDOWS\DUMP52f2.tmp
2008-09-04 19:57 90,112 ----a-w C:\WINDOWS\DUMP536f.tmp
2008-09-04 19:55 90,112 ----a-w C:\WINDOWS\DUMP5350.tmp
2008-09-04 19:54 90,112 ----a-w C:\WINDOWS\DUMP52d4.tmp
2008-09-04 19:51 90,112 ----a-w C:\WINDOWS\DUMP4d26.tmp
2008-09-04 19:50 90,112 ----a-w C:\WINDOWS\DUMP53fc.tmp
2008-09-04 19:49 90,112 ----a-w C:\WINDOWS\DUMP54f6.tmp
2008-09-04 19:47 90,112 ----a-w C:\WINDOWS\DUMP540b.tmp
2008-09-04 19:46 90,112 ----a-w C:\WINDOWS\DUMP53be.tmp
2008-09-04 19:45 90,112 ----a-w C:\WINDOWS\DUMP5380.tmp
2008-09-04 19:43 90,112 ----a-w C:\WINDOWS\DUMP5469.tmp
2008-09-04 19:42 90,112 ----a-w C:\WINDOWS\DUMP5341.tmp
2008-09-04 19:41 90,112 ----a-w C:\WINDOWS\DUMP5321.tmp
2008-09-04 19:39 90,112 ----a-w C:\WINDOWS\DUMP537f.tmp
2008-09-04 19:38 90,112 ----a-w C:\WINDOWS\DUMP539f.tmp
2008-09-04 19:37 90,112 ----a-w C:\WINDOWS\DUMP4cf7.tmp
2008-09-04 19:35 90,112 ----a-w C:\WINDOWS\DUMP53bd.tmp
2008-09-04 19:34 90,112 ----a-w C:\WINDOWS\DUMP5330.tmp
2008-09-04 19:33 90,112 ----a-w C:\WINDOWS\DUMP5488.tmp
2008-09-04 19:30 90,112 ----a-w C:\WINDOWS\DUMP52d3.tmp
2008-09-04 19:27 90,112 ----a-w C:\WINDOWS\DUMP541c.tmp
2008-09-04 19:26 90,112 ----a-w C:\WINDOWS\DUMP55d0.tmp
2008-09-04 19:24 90,112 ----a-w C:\WINDOWS\DUMP5340.tmp
2008-09-04 19:23 90,112 ----a-w C:\WINDOWS\DUMP541b.tmp
2008-09-04 19:22 90,112 ----a-w C:\WINDOWS\DUMP5505.tmp
2008-09-04 19:20 90,112 ----a-w C:\WINDOWS\DUMP52e2.tmp
2008-09-04 19:19 90,112 ----a-w C:\WINDOWS\DUMP5302.tmp
2008-09-04 19:18 90,112 ----a-w C:\WINDOWS\DUMP544a.tmp
2008-09-04 19:16 90,112 ----a-w C:\WINDOWS\DUMP539e.tmp
2008-09-04 19:15 90,112 ----a-w C:\WINDOWS\DUMP5311.tmp
2008-09-04 19:14 90,112 ----a-w C:\WINDOWS\DUMP4cd8.tmp
2008-09-04 19:12 90,112 ----a-w C:\WINDOWS\DUMP535f.tmp
2008-09-04 19:09 90,112 ----a-w C:\WINDOWS\DUMP4e8d.tmp
2008-09-04 19:08 90,112 ----a-w C:\WINDOWS\DUMP4cd7.tmp
2008-09-04 19:03 90,112 ----a-w C:\WINDOWS\DUMP4db2.tmp
2008-09-04 18:58 90,112 ----a-w C:\WINDOWS\DUMP416e.tmp
2008-09-04 18:57 90,112 ----a-w C:\WINDOWS\DUMP4759.tmp
2008-09-04 18:56 90,112 ----a-w C:\WINDOWS\DUMP4a86.tmp
2008-09-04 18:53 90,112 ----a-w C:\WINDOWS\DUMP5582.tmp
2008-09-04 13:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-03 19:09 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-31 22:29 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-31 22:23 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-31 22:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-31 22:22 --------- d-----w C:\Program Files\MsgThemes
2008-08-30 19:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-30 17:36 --------- d-----w C:\Program Files\a-squared Free
2008-08-13 20:34 --------- d-----w C:\Program Files\Google
2006-11-27 18:20 314 ----a-w C:\Program Files\INSTALL.LOG
2006-11-10 15:44 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-09-05 66912]
[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-09-05 13:55 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-20 180269]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 196608]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-06-04 286720]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 155648]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 98304]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [2008-09-05 278264]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\cfp.exe" [2008-09-05 1655552]
"SiSPower"="SiSPower.dll" [2004-09-24 C:\WINDOWS\system32\SiSPower.dll]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 C:\WINDOWS\AGRSMMSG.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 C:\WINDOWS\ALCXMNTR.EXE]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe [2004-10-20 45056]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-01-11 125624]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-09-05 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-09-05 24208]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-VTTimer - VTTimer.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\wwzh41zb.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-05 16:17:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-09-05 16:21:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-05 23:21:34
Pre-Run: 58,208,714,752 bytes free
Post-Run: 58,200,678,400 bytes free
I think the ComboFix is on the top of this page.
Was this file too big?
I hope this is right, now.
Thanks,
Nate G.